Skip to content

CVE-2023-38255 | MODULYS GP (MOD3GP-SY-120K)

A potential attacker with or without (cookie theft) access to the device would be able to include malicious code (XSS) when uploading new device configuration that could affect the intended function of the device. .This CVE has a CVSS3.1 score of 6.5 and a Base Severity of MEDIUM.

InfoDetails
CVE IDCVE-2023-38255
CVE StatePUBLISHED
BaseScore6.5
BaseSeverityMEDIUM
VectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
VersionNA

References for CVE-2023-38255 :
https://www.cisa.gov/news-events/ics-advisories/icsa-23-250-03

Metric TypeMetric Score
AttackVector(AV)NETWORK
AttackComplexity(AC)LOW
PrivilegesRequired(PR)NONE
UserInteraction(UI)NONE
Scope(S)UNCHANGED
Confidentiality(C)LOW
Availability(A)NONE
Integrity(I)LOW