CVE-2024-5849
HIGHDescription
An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.
Is your site exposed to CVE-2024-5849?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| pepperl-fuchs | icdm-rx\/tcp_socketserver_firmware |
| pepperl-fuchs | icdm-rx\/tcp-16db9\/rj45-rm |
| pepperl-fuchs | icdm-rx\/tcp-16rj45\/2rj45-pm |
| pepperl-fuchs | icdm-rx\/tcp-16rj45\/rj45-rm |
| pepperl-fuchs | icdm-rx\/tcp-2db9\/rj45-din |
| pepperl-fuchs | icdm-rx\/tcp-2st\/rj45-din |
| pepperl-fuchs | icdm-rx\/tcp-32rj45\/rj45-rm |
| pepperl-fuchs | icdm-rx\/tcp-4db9\/2rj45-din |
| pepperl-fuchs | icdm-rx\/tcp-4db9\/2rj45-pm |
| pepperl-fuchs | icdm-rx\/tcp-8db9\/2rj45-pm |
| pepperl-fuchs | icdm-rx\/tcp-db9\/rj45-din |
| pepperl-fuchs | icdm-rx\/tcp-db9\/rj45-pm |
| pepperl-fuchs | icdm-rx\/tcp-db9\/rj45-pm2 |
| pepperl-fuchs | icdm-rx\/tcp-st\/rj45-din |
| pepperl-fuchs | profinet_firmware |
| pepperl-fuchs | icdm-rx\/pn-2db9\/rj45-din |
| pepperl-fuchs | icdm-rx\/pn-2st\/rj45-din |
| pepperl-fuchs | icdm-rx\/pn-4db9\/2rj45-din |
| pepperl-fuchs | icdm-rx\/pn-db9\/rj45-din |
| pepperl-fuchs | icdm-rx\/pn-db9\/rj45-pm |
| pepperl-fuchs | icdm-rx\/pn-st\/rj45-din |
| pepperl-fuchs | profinet\/modbus_firmware |
| pepperl-fuchs | icdm-rx\/pn1-2db9\/rj45-din |
| pepperl-fuchs | icdm-rx\/pn1-2st\/rj45-din |
| pepperl-fuchs | icdm-rx\/pn1-4db9\/2rj45-din |
| pepperl-fuchs | icdm-rx\/pn1-db9\/rj45-din |
| pepperl-fuchs | icdm-rx\/pn1-db9\/rj45-pm |
| pepperl-fuchs | icdm-rx\/pn1-st\/rj45-din |
| pepperl-fuchs | modbus_router_firmware |
| pepperl-fuchs | modbus_server_firmware |
| pepperl-fuchs | modbus_tcp_firmware |
| pepperl-fuchs | icdm-rx\/mod-4db9\/2rj45-din |
| pepperl-fuchs | icdm-rx\/mod-db9\/rj45-din |
| pepperl-fuchs | icdm-rx\/mod-st\/rj45-din |
| pepperl-fuchs | ethernet\/ip_firmware |
| pepperl-fuchs | icdm-rx\/en-2db9\/rj45-din |
| pepperl-fuchs | icdm-rx\/en-2st\/rj45-din |
| pepperl-fuchs | icdm-rx\/en-4db9\/2rj45-din |
| pepperl-fuchs | icdm-rx\/en-db9\/rj45-din |
| pepperl-fuchs | icdm-rx\/en-db9\/rj45-pm |
| pepperl-fuchs | icdm-rx\/en-st\/rj45-din |
| pepperl-fuchs | eip\/modbus_firmware |
| pepperl-fuchs | icdm-rx\/en1-2db9\/rj45-din |
| pepperl-fuchs | icdm-rx\/en1-2st\/rj45-din |
| pepperl-fuchs | icdm-rx\/en1-4db9\/2rj45-din |
| pepperl-fuchs | icdm-rx\/en1-db9\/rj45-din |
| pepperl-fuchs | icdm-rx\/en1-db9\/rj45-pm |
| pepperl-fuchs | icdm-rx\/en1-st\/rj45-din |
References
Other References
Frequently Asked Questions
What is CVE-2024-5849? +
How severe is CVE-2024-5849? +
What products are affected by CVE-2024-5849? +
How do I check if I'm vulnerable to CVE-2024-5849? +
Related Vulnerabilities
WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows …
Reflected Cross-Site Scripting (XSS) vulnerability in Navigate Content Management System. The vulnerability is present in the '/blog' endpoint because user …
Cross-Site Scripting (XSS) vulnerability reflected in Semantic MediaWiki. This vulnerability allows an attacker to execute JavaScript code in the victim's …
Bludit CMS prior to commit 6732dde contains a reflected cross-site scripting vulnerability in the search plugin that allows unauthenticated attackers …
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the admin dashboard's Autodiscover …
mailcow: dockerized is an open source groupware/email suite based on docker. In versions prior to 2026-03b, the mailcow web interface …