RULE(RULE ID:333901)

Rule General Information
Release Date: 2021-09-14
Rule Name: Advantech R-SeeNet Cross Site Scripting Vulnerability (CVE-2021-21799)
Severity:
CVE ID:
Rule Protection Details
Description: Cross-site scripting vulnerabilities exist in the telnet_form.php script functionality of Advantech R-SeeNet v 2.4.12 (20.10.2020). If a user visits a specially crafted URL, it can lead to arbitrary JavaScript code execution in the context of the targeted user’s browser. An attacker can provide a crafted URL to trigger this vulnerability.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux
Reference: https://talosintelligence.com/vulnerability_reports/TALOS-2021-1270
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://ep.advantech-bb.cz/products/software/r-seenet