CVE-2023-46344 is a stored cross-site scripting (XSS) vulnerability in Solar-Log Base 15 Firmware 6.0.1 Build 161, and potentially other Solar-Log Base products, specifically affecting the switch group function. This medium-severity vulnerability (CVSS 5.4) allows an authenticated attacker to escalate privileges to an installer or PM role, which can then be leveraged for administrative access and further attacks. While the vendor claims a fix was issued in 2013 for some models, the current status for Solar-Log Base products remains a concern. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.10.2019CPE matchmatch criteria | cpe:2.3:o:solar-log:2000_pm\+_firmware:15.10.2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.