Medium severity6.1NVD Advisory· Published Feb 24, 2022· Updated Jun 17, 2026
CVE-2020-14502
CVE-2020-14502
Description
The web interface of the 1734-AENTR communication module is vulnerable to stored XSS. A remote, unauthenticated attacker could store a malicious script within the web interface that, when executed, could modify some string values on the homepage of the web interface.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:o:rockwellautomation:1734-aentr_point_i\/o_dual_port_network_adaptor_series_b_firmware:*:*:*:*:*:*:*:*Range: >=4.001,<=4.005
cpe:2.3:o:rockwellautomation:1734-aentr_point_i\/o_dual_port_network_adaptor_series_c_firmware:6.011:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:rockwellautomation:1734-aentr_point_i\/o_dual_port_network_adaptor_series_c_firmware:6.011:*:*:*:*:*:*:*
- cpe:2.3:o:rockwellautomation:1734-aentr_point_i\/o_dual_port_network_adaptor_series_c_firmware:6.012:*:*:*:*:*:*:*
- Range: Series B 4.001 to 4.005, and 5.011 to 5.017
Patches
Vulnerability mechanics
References
1- www.cisa.gov/uscert/ics/advisories/icsa-21-063-01nvdMitigationThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.