Medium severity6.1NVD Advisory· Published Aug 13, 2024· Updated Jun 17, 2026
CVE-2024-38501
CVE-2024-38501
Description
An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15- cpe:2.3:o:pepperl-fuchs:eip\/modbus_firmware:*:*:*:*:*:*:*:*Range: <1.08
- cpe:2.3:o:pepperl-fuchs:ethernet\/ip_firmware:*:*:*:*:*:*:*:*Range: <7.22
- cpe:2.3:o:pepperl-fuchs:icdm-rx\/tcp_socketserver_firmware:*:*:*:*:*:*:*:*Range: <11.65
- cpe:2.3:o:pepperl-fuchs:modbus_router_firmware:*:*:*:*:*:*:*:*Range: <7.09
- cpe:2.3:o:pepperl-fuchs:modbus_server_firmware:*:*:*:*:*:*:*:*Range: <7.11
- cpe:2.3:o:pepperl-fuchs:modbus_tcp_firmware:*:*:*:*:*:*:*:*Range: <7.11
- cpe:2.3:o:pepperl-fuchs:profinet\/modbus_firmware:*:*:*:*:*:*:*:*Range: <1.0.7
- cpe:2.3:o:pepperl-fuchs:profinet_firmware:*:*:*:*:*:*:*:*Range: <3.4.9
- Range: PROFINET
- Range: EtherNet/IP
EIP/Modbus+ 1 more
- (no CPE)range: EIP/Modbus
- (no CPE)range: EIP/Modbus
EIP/Modbus+ 1 more
- (no CPE)range: EIP/Modbus
- (no CPE)range: PROFINET/Modbus
- Range: SocketServer
Patches
Vulnerability mechanics
References
1- cert.vde.com/en/advisories/VDE-2024-033nvdThird Party Advisory
News mentions
0No linked articles in our index yet.