CVE-2024-3141 is a problematic cross-site scripting (XSS) vulnerability affecting Clavister E10 and E80 devices running versions up to 14.00.10. This flaw resides in the Misc Settings Page, specifically when manipulating various arguments like WatchdogTimerTime or AVCache Lifetime. The vulnerability has a low CVSS score of 2.4, indicating a low severity due to the high privileges required for exploitation and limited impact (no confidentiality or availability impact, only low integrity). While the exploit has been publicly disclosed, there is no evidence of active exploitation, exploit code in common frameworks, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Clavister | E10 | 14.00.0, 14.00.1, 14.00.10, 14.00.2, 14.00.3, 14.00.4, 14.00.5, 14.00.6, 14.00.7, 14.00.8, 14.00.9CNA affected | |
| Clavister | E80 | 14.00.0, 14.00.1, 14.00.10, 14.00.2, 14.00.3, 14.00.4, 14.00.5, 14.00.6, 14.00.7, 14.00.8, 14.00.9CNA affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.