{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-41725","assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","state":"PUBLISHED","assignerShortName":"icscert","dateReserved":"2024-09-05T20:11:00.306Z","datePublished":"2024-09-24T23:44:04.492Z","dateUpdated":"2024-09-25T17:01:33.873Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"ProGauge MAGLINK LX CONSOLE","vendor":"Dover Fueling Solutions (DFS)","versions":[{"lessThanOrEqual":"3.4.2.2.6","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"ProGauge MAGLINK LX4 CONSOLE","vendor":"Dover Fueling Solutions (DFS)","versions":[{"lessThanOrEqual":"4.17.9e","status":"affected","version":"0","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"Pedro Umbelino of Bitsight reported these vulnerabilities to CISA."}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input \nfields that are used to render pages which may allow cross site \nscripting."}],"value":"ProGauge MAGLINK LX CONSOLE does not have sufficient filtering on input \nfields that are used to render pages which may allow cross site \nscripting."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]},{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.7,"baseSeverity":"HIGH","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"PASSIVE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"CWE-79 Cross-site Scripting","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert","dateUpdated":"2024-09-24T23:44:04.492Z"},"references":[{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-24-268-04"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Dover Fueling Solutions released a new software update version 4.19.10 \nfor the MagLink LX console to address these vulnerabilities. The \nsoftware release is available for installation on consoles through DFS's\n authorized service organizations in North America. North American users\n can reach DFS's customer support team by telephone at 877-679-8324.\n\n<br>"}],"value":"Dover Fueling Solutions released a new software update version 4.19.10 \nfor the MagLink LX console to address these vulnerabilities. The \nsoftware release is available for installation on consoles through DFS's\n authorized service organizations in North America. North American users\n can reach DFS's customer support team by telephone at 877-679-8324."}],"source":{"advisory":"ICSA-24-268-04","discovery":"EXTERNAL"},"title":"Dover Fueling Solutions ProGauge MAGLINK LX CONSOLE Cross-site Scripting","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>DFS strongly encourages users of MagLink products to:</p>\n<ul>\n<li>Install MagLink consoles behind firewalls for security.</li>\n<li>Monitor and install updates on a timely basis.</li>\n<li>Contact DFS customer support with any questions about operations or updates of MagLink software.</li>\n</ul>\n<p>Alternatively, MagLink may operate offfline or disconnected from a network.</p>\n<p>Registered MagLink customers have access to technical information, \nupdates, and technical bulletins via a DFS proprietary portal.</p>\n\n<br>"}],"value":"DFS strongly encourages users of MagLink products to:\n\n\n\n  *  Install MagLink consoles behind firewalls for security.\n\n  *  Monitor and install updates on a timely basis.\n\n  *  Contact DFS customer support with any questions about operations or updates of MagLink software.\n\n\n\n\nAlternatively, MagLink may operate offfline or disconnected from a network.\n\n\nRegistered MagLink customers have access to technical information, \nupdates, and technical bulletins via a DFS proprietary portal."}],"x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"affected":[{"vendor":"doverfuelingsolutions","product":"maglink_lx_console","cpes":["cpe:2.3:a:doverfuelingsolutions:maglink_lx_console:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","versions":[{"version":"0","status":"affected","lessThanOrEqual":"3.4.2.2.6","versionType":"custom"}]},{"vendor":"doverfuelingsolutions","product":"maglink_lx4_console","cpes":["cpe:2.3:a:doverfuelingsolutions:maglink_lx4_console:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","versions":[{"version":"0","status":"affected","lessThanOrEqual":"4.17.9e","versionType":"custom"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-09-25T17:00:46.641525Z","id":"CVE-2024-41725","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-25T17:01:33.873Z"}}]}}