Security for everyone

CVE-2021-21801 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Advantech R-SeeNet affects v. 2.4.12 (20.10.2020).

SCAN NOW

Short Info


Level

Medium

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 sec

Scan only one

Url

Source

-

Advantech R-SeeNet is a web application used for device management, monitoring, and visualization. It provides a user-friendly interface for managing industrial automation devices, such as programmable logic controllers (PLCs), HMIs, and other devices connected to a network. With its advanced features, the Advantech R-SeeNet aims to provide enhanced efficiency and productivity to industrial automation processes.

One of the critical vulnerabilities detected in the Advantech R-SeeNet is CVE-2021-21801. The vulnerability is present in the device_graph_page.php script and can allow an attacker to execute arbitrary JavaScript code on the target system. This can lead to unauthorized access to sensitive information, alteration of system configurations, and even complete system takeover.

When exploited, the CVE-2021-21801 vulnerability can be highly damaging to a system. An attacker can use this vulnerability to perform various malicious actions, including stealing confidential data, manipulating device settings, installing malware, and disrupting normal system operations. Furthermore, the exploitation of this vulnerability can lead to significant financial losses, downtime, and reputational damage.

Thanks to the pro features of the securityforeveryone.com platform, users can easily and quickly learn about vulnerabilities in their digital assets. The platform provides advanced scanning tools, real-time alerts, and expert analysis to identify and remediate vulnerabilities promptly. By using this platform, businesses can ensure that their digital assets are secure and protected against cybersecurity threats.

 

REFERENCES

cyber security services for everyone one. Free security tools, continuous vulnerability scanning and many more.
Try it yourself,
control security posture