vendor:
Alice Modem
by:
7.5
CVSS
HIGH
Cross-Site Scripting, Denial-of-Service
CWE
Product Name: Alice Modem
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Alice Modem Cross-Site Scripting and Denial-of-Service Vulnerability
The Alice Modem is prone to a cross-site scripting vulnerability and a denial-of-service vulnerability due to improper handling of user-supplied input. An attacker can exploit these vulnerabilities to cause a denial-of-service condition or execute arbitrary script code in the browser of a user visiting the affected site. Successful exploitation of the cross-site scripting vulnerability may result in the theft of cookie-based authentication credentials and enable further attacks.
Mitigation:
It is recommended to update the Alice Modem firmware to the latest version to mitigate these vulnerabilities.