CVE Database
/

CVE-2020-14502

Back to search

CVE-2020-14502

Published: Feb 24, 2022

Modified: Apr 17, 2025

PUBLISHED

Description

The web interface of the 1734-AENTR communication module is vulnerable to stored XSS. A remote, unauthenticated attacker could store a malicious script within the web interface that, when executed, could modify some string values on the homepage of the web interface.

VendorProductVersions

Rockwell Automation

1734-AENTR

affected
Series B 4.001 to 4.005, and 5.011 to 5.017
affected
Series C 6.011 and 6.012

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now