← back
CVE-2024-3776

Netvision airPASS - Reflected XSS

CVSS 6.1 MEDIUMEPSS 0.4%CWE-79
The parameter used in the login page of Netvision airPASS is not properly filtered for user input. An unauthenticated remote attacker can insert JavaScript code to the parameter for Reflected Cross-site scripting attacks.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
Netvision · airPASS

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →