A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious user to view and modify sensitive data or make the webpage unavailable. The vulnerability stems from missing special character filtering and encoding. Successful exploitation requires an attacker to be able to update configuration fields behind admin login.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rockwellautomation
Rockwellautomation 1783-natr |
|
| Vendors & Products |
Rockwellautomation
Rockwellautomation 1783-natr |
Tue, 14 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 14 Oct 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious user to view and modify sensitive data or make the webpage unavailable. The vulnerability stems from missing special character filtering and encoding. Successful exploitation requires an attacker to be able to update configuration fields behind admin login. | |
| Title | Rockwell Automation Comms - 1783-NATR Stored Cross-Site Scripting Vulnerability | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Rockwell
Published: 2025-10-14T12:37:44.866Z
Updated: 2025-10-14T13:18:03.602Z
Reserved: 2025-07-07T18:50:24.416Z
Link: CVE-2025-7329
Updated: 2025-10-14T13:17:57.538Z
Status : Awaiting Analysis
Published: 2025-10-14T13:15:39.157
Modified: 2025-10-14T19:36:29.240
Link: CVE-2025-7329
No data.