CVE-2024-5410: Stored Cross-Site Scripting
Missing input validation in the ORing IAP-420 web-interface allows stored Cross-Site Scripting (XSS).This issue affects IAP-420 version 2.01e and below.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
IAP-420to a version that resolves this vulnerability.Fixed in 2.01e - Compensating control
Mitigate the stored XSS in the IAP-420 web-interface by reducing exposure of the web-interface (e.g., restrict access to the IAP-420 web-interface to trusted users/IPs) until patched, because the issue affects IAP-420 version 2.01e and below.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5410?
CVE-2024-5410 is classified as a high-severity vulnerability due to its potential to allow stored Cross-Site Scripting (XSS).
How do I fix CVE-2024-5410?
To fix CVE-2024-5410, upgrade the ORing IAP-420 firmware to version 2.01f or later, which addresses the input validation issue.
What versions of ORing IAP-420 are affected by CVE-2024-5410?
CVE-2024-5410 affects ORing IAP-420 versions 2.01e and below.
What type of vulnerability is CVE-2024-5410?
CVE-2024-5410 is a stored Cross-Site Scripting (XSS) vulnerability due to missing input validation.
How can CVE-2024-5410 be exploited?
CVE-2024-5410 can be exploited by attackers injecting malicious scripts through the web-interface, which could execute in users' browsers.