Vulnerability Description
The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting vulnerability, which could allow an attacker to inject arbitrary scripts into the endpoint of a web interface that could run malicious javascript code during a user's session.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Controlbyweb | X-332-24I Firmware | 1.06 |
| Controlbyweb | X-332-24I | - |
| Controlbyweb | X-301-I Firmware | 1.15 |
| Controlbyweb | X-301-I | - |
| Controlbyweb | X-301-24I Firmware | 1.15 |
| Controlbyweb | X-301-24I | - |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-341-05PatchThird Party AdvisoryUS Government Resource
- https://www.cisa.gov/news-events/ics-advisories/icsa-23-341-05PatchThird Party AdvisoryUS Government Resource
FAQ
What is CVE-2023-6333?
CVE-2023-6333 is a vulnerability with a CVSS score of 7.5 (HIGH). The affected ControlByWeb Relay products are vulnerable to a stored cross-site scripting vulnerability, which could allow an attacker to inject arbitrary scripts into the endpoint of a web interface ...
How severe is CVE-2023-6333?
CVE-2023-6333 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-6333?
Check the references section above for vendor advisories and patch information. Affected products include: Controlbyweb X-332-24I Firmware, Controlbyweb X-332-24I, Controlbyweb X-301-I Firmware, Controlbyweb X-301-I, Controlbyweb X-301-24I Firmware.