CVE Feed

    Dashboard / CVE / CVE-2024-6558

    CVE-2024-6558

    HMS Industrial Networks Anybus-CompactCom 30 products are vulnerable to a XSS attack caused by the lack of input sanitation checks. As a consequence, it is possible to insert HTML code into input fields and store the HTML code. The stored HTML code will be embedded in the page and executed by host browser the next time the page is loaded, enabling social engineering attacks.

    Published:Jul 25, 2024
    Last Modified:Aug 27, 2025
    EPS:Jul 25, 2024
    EPSS Score:0.00472
    CVSS Score:6.3

    Affected Products

    Vendor
    Hms-networks
    Product
    Anybus Compactcom 30 Module Ethernet\/ip
    Vendor
    Hms-networks
    Product
    Anybus Compactcom 30 Module Ethernet\/ip Firmware
    Vendor
    Hms-networks
    Product
    Anybus Compactcom 30 Module Usb Without Housing
    Vendor
    Hms-networks
    Product
    Anybus Compactcom 30 Module Usb Without Housing Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High