SaTECH BCU, in its firmware version 2.1.3, could allow XSS attacks and other malicious resources to be stored on the web server. An attacker with some knowledge of the web application could send a malicious request to the victim users. Through this request, the victims would interpret the code (resources) stored on another malicious website owned by the attacker.
History

Fri, 28 Mar 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description SaTECH BCU, in its firmware version 2.1.3, could allow XSS attacks and other malicious resources to be stored on the web server. An attacker with some knowledge of the web application could send a malicious request to the victim users. Through this request, the victims would interpret the code (resources) stored on another malicious website owned by the attacker.
Title Reflected Cross-Site Scripting (XSS) vulnerability in saTECH BCU
Weaknesses CWE-942
References
Metrics cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-03-28T14:32:18.569Z

Reserved: 2025-03-27T10:59:45.540Z

Link: CVE-2025-2865

cve-icon Vulnrichment

Updated: 2025-03-28T14:32:14.515Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-28T14:15:21.727

Modified: 2025-03-28T18:11:40.180

Link: CVE-2025-2865

cve-icon Redhat

No data.