CHIYU.TCP.IP.Converter.Multiple.XSS
Description
This indicates an attack attempt against a Cross Site Scripting vulnerability in CHIYU IoT devices.
The vulnerability is due to insufficient sanitizing of user supplied inputs in the application while handling maliciously crafted requests. An attacker can exploit this by tricking an unsuspecting user into visiting a malicious webpage and execute arbitrary script code within the context of the users' browser.
Affected Products
BF-430 all firmware versions prior to June 2021
BF-431 all firmware versions prior to June 2021
BF-450M all firmware versions prior to June 2021
BF-630 all firmware versions prior to June 2021
BF631-W all firmware versions prior to June 2021
BF830-W all firmware versions prior to June 2021
Webpass all firmware versions prior to June 2021
BF-MINI-W all firmware versions prior to June 2021
SEMAC all firmware versions prior to June 2021
Impact
System Compromise: Remote attackers can execute arbitrary script code within the context of the target user's browser
Recommended Actions
Apply the most recent upgrade or patch from the vendor
https://www.chiyu-tech.com/msg/msg88.html
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2021-10-20 | 18.182 | Default_action:pass:drop |
2021-08-19 | 18.143 | Sig Added |
2021-08-16 | 18.140 |