CVE Intelligence
Skip to main content
HIGH

CVE-2024-38502

CVE-2024-38502 — Pepperl+Fuchs: Device Master ICDM-RX/* XSS vulnerability allows stored XSS

An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.

Published Updated Sources: cvelistV5, CERTVDE

Triage

Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.

Exploitation

Unreported

no source claims exploitation

EPSS

0%

chance of exploitation in 30 days

Affects

pepperl fuchs

44 products listed

CVSS base

7.1

HIGH

CISA SSVC assessment

Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.

CISA

Exploitation

None

none · proof-of-concept · active

Automatable

No

can an attacker script all four kill-chain steps

Technical impact

Partial

partial · total control of the vulnerable component

Affected scope

The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.

Vendors (1)

Products (44)

icdm rx tcp db9 rj45 dinicdm rx tcp st rj45 dinicdm rx tcp 4db9 2rj45 dinicdm rx tcp db9 rj45 pmicdm rx tcp 2db9 rj45 dinicdm rx tcp 2st rj45 dinicdm rx tcp 4db9 2rj45 pmicdm rx tcp 8db9 2rj45 pmicdm rx tcp 16rj45 rj45 rmicdm rx tcp 16db9 rj45 rmicdm rx tcp 32rj45 rj45 rmicdm rx tcp db9 rj45 pm2icdm rx tcp 16rj45 2rj45 pmicdm rx pn db9 rj45 dinicdm rx pn st rj45 dinicdm rx pn 4db9 2rj45 dinicdm rx pn db9 rj45 pmicdm rx pn 2db9 rj45 dinicdm rx pn 2st rj45 dinicdm rx pn1 db9 rj45 pmicdm rx pn1 db9 rj45 dinicdm rx pn1 st rj45 dinicdm rx pn1 2db9 rj45 dinicdm rx pn1 4db9 2rj45 dinicdm rx pn1 2st rj45 dinicdm rx en db9 rj45 dinicdm rx en st rj45 dinicdm rx en 4db9 2rj45 dinicdm rx en db9 rj45 pmicdm rx en 2db9 rj45 dinicdm rx en 2st rj45 dinicdm rx en1 db9 rj45 pmicdm rx en1 db9 rj45 dinicdm rx en1 st rj45 dinicdm rx en1 2db9 rj45 dinicdm rx en1 4db9 2rj45 dinicdm rx en1 2st rj45 dinicdm rx mod db9 rj45 dinicdm rx mod st rj45 dinicdm rx mod 4db9 2rj45 dinicdm rx mod db9 rj45 pmicdm rx mod 2db9 rj45 dinicdm rx mod 2st rj45 dinicdm rx mod 16rj45 2rj45 pm

Every base score collected

Sources score independently and disagree; each row says who scored it and under which version.

ScoreVersionSeverityExpl.ImpactSource
7.1CVSS 3.1HIGHcvelistV5

Weakness & attack patterns

  • CWE-79

References

1 on the record

Elsewhere on this site

Not in any source we poll

Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.

  • No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
  • No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
  • No exploit packet captures, log samples, or incident case IDs supplied.