« Volver al listado

CVE-2026-42366

Estado: AnalizadaMedia (6.1)—

Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-42366",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-42366",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-04T12:59:04.201448Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "0df08a0e-a200-4957-9bb0-084f562506f9",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.4,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "0df08a0e-a200-4957-9bb0-084f562506f9",
      "affectedData": [
        {
          "vendor": "GeoVision Inc.",
          "product": "GV-LPC2011/LPC2211",
          "versions": [
            {
              "status": "affected",
              "version": "V1.10"
            },
            {
              "status": "unaffected",
              "version": "V1.20"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-05-04T01:16:03.753",
  "references": [
    {
      "url": "https://talosintelligence.com/vulnerability_reports/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "0df08a0e-a200-4957-9bb0-084f562506f9"
    },
    {
      "url": "https://www.geovision.com.tw/cyber_security.php",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "0df08a0e-a200-4957-9bb0-084f562506f9"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "0df08a0e-a200-4957-9bb0-084f562506f9",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple reflected cross-site scripting (xss) vulnerabilities exist in the Web Interface / ssi.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted malicious url can lead to an arbitrary javascript code execution. An attacker can provide a crafted URL to trigger this vulnerability."
    }
  ],
  "lastModified": "2026-06-17T10:47:44.987",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:geovision:gv-lpc2011_firmware:1.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C1E349A9-4EEF-40B6-89A0-86242C2ADBC5"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:geovision:gv-lpc2011:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "87CE78D0-0894-451F-9A70-4F2A8062EC8A"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:geovision:gv-lpc2211_firmware:1.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F3B818E-22D3-400A-AF2C-DEA66280464A"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:geovision:gv-lpc2211:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "59F15521-B4F3-4CCA-8C03-0A4EA2864C6E"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "0df08a0e-a200-4957-9bb0-084f562506f9"
}