CVE-2023-4667 - CVE House
Back to Database
Status published High CVE-2023-4667

Stored Cross Site Scripting in webserver administration

Vulnerability Description

The web interface of the PAC Device allows the device administrator user profile to store malicious scripts in some fields. The stored malicious script is then executed when the GUI is opened by any users of the webserver administration interface.  The root cause of the vulnerability is inadequate input validation and output encoding in the web administration interface component of the firmware. This could lead to  unauthorized access and data leakage

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-4667

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SIGMA Lite & Lite +, SIGMA Wide, SIGMA Extreme, MorphoWave Compact/XP, VisionPass, MorphoWave SP
Vulnerable Versions:
0

Timeline

Official Publish: November 28th, 2023
Last Modified: October 17th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N

Weaknesses (CWE)