An issue was discovered on RLE Wi-MGR/FDS-Wi 6.2 devices. Persistent XSS exists in the web server. Remote attackers can inject malicious JavaScript code using the device's BACnet implementation. This is similar to a Cross Protocol Injection with SNMP.
References
Link | Resource |
---|---|
http://misteralfa-hack.blogspot.com/2018/02/bacnet-entrando-en-materia.html | Exploit Third Party Advisory |
Information
Published : 2018-02-20 17:29
Updated : 2018-03-21 06:31
NVD link : CVE-2018-7277
Mitre link : CVE-2018-7277
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
rletech
- wi-mgr_firmware
- wi-mgr
- fds-wi
- fds-wi_firmware