VYPR

S2020 Firmware

by Ge

CVEs (3)

  • CVE-2020-16246MedOct 20, 2020
    risk 0.40cvss 6.1epss 0.01

    The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow attackers to trick users into following a link or navigating to a page that posts a malicious JavaScript statement to the vulnerable site, causing the malicious JavaScript to be…

  • CVE-2020-16242MedSep 25, 2020
    risk 0.40cvss 6.1epss 0.01

    The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow an attacker to trick application users into performing critical application actions that include, but are not limited to, adding and updating accounts.

  • CVE-2019-18267MedDec 18, 2019
    risk 0.35cvss 5.4epss 0.02

    An issue was found in GE S2020/S2020G Fast Switch 61850, S2020/S2020G Fast Switch 61850 Versions 07A03 and prior. An attacker can inject arbitrary Javascript in a specially crafted HTTP request that may be reflected back in the HTTP response. The device is also vulnerable to a…