CVE-2020-16246 - CVE House
Back to Database
Status published Medium CVE-2020-16246

GE Reason S20 Ethernet Switch

Vulnerability Description

The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow attackers to trick users into following a link or navigating to a page that posts a malicious JavaScript statement to the vulnerable site, causing the malicious JavaScript to be rendered by the site and executed by the victim client.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-16246

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

General Electric

View all reports →

Affected Software

Reason S20 Ethernet Switch
Vulnerable Versions:
S2020, S2024

Timeline

Official Publish: October 20th, 2020
Last Modified: September 17th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Weaknesses (CWE)