Vulnerability Description
When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed into configuration mode the web servers “Garage Door Control Module Setup” page is vulnerable to XSS via a broadcast SSID name containing malicious code with client side Java Script and/or HTML. This allows the attacker to inject malicious code with client side Java Script and/or HTML into the users' web browser.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Geniecompany | Aladdin Connect Garage Door Opener Firmware | <= 14.1.1 |
| Geniecompany | Aladdin Connect Garage Door Opener | - |
Related Weaknesses (CWE)
References
- https://www.rapid7.com/blog/post/2024/01/03/genie-aladdin-connect-retrofit-garagMitigationVendor Advisory
- https://www.rapid7.com/blog/post/2024/01/03/genie-aladdin-connect-retrofit-garagMitigationVendor Advisory
FAQ
What is CVE-2023-5880?
CVE-2023-5880 is a vulnerability with a CVSS score of 8.8 (HIGH). When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed into configuration mode the web servers “Garage Door Control Module Setup” page is vulnerable to XSS via ...
How severe is CVE-2023-5880?
CVE-2023-5880 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-5880?
Check the references section above for vendor advisories and patch information. Affected products include: Geniecompany Aladdin Connect Garage Door Opener Firmware, Geniecompany Aladdin Connect Garage Door Opener.