MEDIUM · 5.4

CVE-2024-0317

Cross-Site Scripting in FireEye EX, affecting version 9.0.3.936727. Exploitation of this vulnerability allows an attacker to send a specially crafted JavaScript payload via the 'type' and 's_f_name' p...

Vulnerability Description

Cross-Site Scripting in FireEye EX, affecting version 9.0.3.936727. Exploitation of this vulnerability allows an attacker to send a specially crafted JavaScript payload via the 'type' and 's_f_name' parameters to an authenticated user to retrieve their session details.

CVSS Score

5.4

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
FireeyeEx 5500 Firmwarea9.0.3.936727
FireeyeEx 5500-
FireeyeEx 8500 Firmware9.0.3.936727
FireeyeEx 8500-
FireeyeEx 3500 Firmware9.0.3.936727
FireeyeEx 3500-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-0317?

CVE-2024-0317 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Cross-Site Scripting in FireEye EX, affecting version 9.0.3.936727. Exploitation of this vulnerability allows an attacker to send a specially crafted JavaScript payload via the 'type' and 's_f_name' p...

How severe is CVE-2024-0317?

CVE-2024-0317 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-0317?

Check the references section above for vendor advisories and patch information. Affected products include: Fireeye Ex 5500 Firmwarea, Fireeye Ex 5500, Fireeye Ex 8500 Firmware, Fireeye Ex 8500, Fireeye Ex 3500 Firmware.