Vulnerability Description
An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pepperl-Fuchs | Icdm-Rx\/Tcp Socketserver Firmware | < 11.65 |
| Pepperl-Fuchs | Icdm-Rx\/Tcp-16Db9\/Rj45-Rm | - |
| Pepperl-Fuchs | Icdm-Rx\/Tcp-16Rj45\/2Rj45-Pm | - |
| Pepperl-Fuchs | Icdm-Rx\/Tcp-16Rj45\/Rj45-Rm | - |
| Pepperl-Fuchs | Icdm-Rx\/Tcp-2Db9\/Rj45-Din | - |
| Pepperl-Fuchs | Icdm-Rx\/Tcp-2St\/Rj45-Din | - |
| Pepperl-Fuchs | Icdm-Rx\/Tcp-32Rj45\/Rj45-Rm | - |
| Pepperl-Fuchs | Icdm-Rx\/Tcp-4Db9\/2Rj45-Din | - |
| Pepperl-Fuchs | Icdm-Rx\/Tcp-4Db9\/2Rj45-Pm | - |
| Pepperl-Fuchs | Icdm-Rx\/Tcp-8Db9\/2Rj45-Pm | - |
| Pepperl-Fuchs | Icdm-Rx\/Tcp-Db9\/Rj45-Din | - |
| Pepperl-Fuchs | Icdm-Rx\/Tcp-Db9\/Rj45-Pm | - |
| Pepperl-Fuchs | Icdm-Rx\/Tcp-Db9\/Rj45-Pm2 | - |
| Pepperl-Fuchs | Icdm-Rx\/Tcp-St\/Rj45-Din | - |
| Pepperl-Fuchs | Profinet Firmware | < 3.4.9 |
| Pepperl-Fuchs | Icdm-Rx\/Pn-2Db9\/Rj45-Din | - |
| Pepperl-Fuchs | Icdm-Rx\/Pn-2St\/Rj45-Din | - |
| Pepperl-Fuchs | Icdm-Rx\/Pn-4Db9\/2Rj45-Din | - |
| Pepperl-Fuchs | Icdm-Rx\/Pn-Db9\/Rj45-Din | - |
| Pepperl-Fuchs | Icdm-Rx\/Pn-Db9\/Rj45-Pm | - |
Related Weaknesses (CWE)
References
- https://cert.vde.com/en/advisories/VDE-2024-033Third Party Advisory
FAQ
What is CVE-2024-38502?
CVE-2024-38502 is a vulnerability with a CVSS score of 7.1 (HIGH). An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.
How severe is CVE-2024-38502?
CVE-2024-38502 has been rated HIGH with a CVSS base score of 7.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-38502?
Check the references section above for vendor advisories and patch information. Affected products include: Pepperl-Fuchs Icdm-Rx\/Tcp Socketserver Firmware, Pepperl-Fuchs Icdm-Rx\/Tcp-16Db9\/Rj45-Rm, Pepperl-Fuchs Icdm-Rx\/Tcp-16Rj45\/2Rj45-Pm, Pepperl-Fuchs Icdm-Rx\/Tcp-16Rj45\/Rj45-Rm, Pepperl-Fuchs Icdm-Rx\/Tcp-2Db9\/Rj45-Din.