S4E just found a critical-severity finding from cve-2022-27924 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Sep 24, 2024

CVE-2024-5420 Scanner

CVE-2024-5420 scanner - Cross-Site Scripting vulnerability in SEH utnserver Pro/ProMAX/INU-100

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-5420
8.3
CVSShigh
Exploitable remotely over the internet · no authentication required.

Missing input validation in the SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 web-interface allows stored Cross-Site Scripting (XSS)..This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below.

Attack Vector
Network
Privileges Req.
None
User Interaction
A
Affected
utnserver Proby SEH Computertechnik
0
utnserver ProMAXby SEH Computertechnik
0
INU-100by SEH Computertechnik
0
utnserver_proby seh
0
Updated Aug 22, 2026View on NVD →
Detail

The SEH utnserver Pro, ProMAX, and INU-100 are devices widely used in network environments for managing printing tasks. Developed for professionals in the IT and telecommunications sectors, these devices provide efficient print server capabilities. Users depend on them for streamlined workflows and device management. However, vulnerabilities in these systems can expose sensitive information and compromise network security. Regular security assessments are crucial for maintaining the integrity of these devices.

The Cross-Site Scripting (XSS) vulnerability in SEH utnserver Pro allows attackers to inject malicious JavaScript code through the device description parameter. This can be exploited remotely, putting users at risk of session hijacking. Attackers can trick users into visiting a malicious link, leading to potential data theft. This vulnerability poses a significant threat to the security of users and their data.

The vulnerable endpoint is located at /device/description_en.html, where an attacker can send a POST request with a malicious payload in the sys_name parameter. The parameter is not properly sanitized, allowing the injection of a script tag. Successful exploitation results in the execution of arbitrary JavaScript in the context of the user's session. This can lead to unauthorized access to sensitive information and user accounts. The vulnerability affects devices running version 20.1.22 and earlier.

If exploited, this vulnerability can allow attackers to hijack user sessions, leading to unauthorized access to sensitive information. They can manipulate user accounts and perform actions as the victim, potentially resulting in data breaches. Users may unknowingly expose their credentials or personal data. Additionally, it could disrupt the functionality of the device, affecting overall network operations.

Join the S4E platform to enhance your cybersecurity posture. With our comprehensive scanning solutions, you can identify vulnerabilities like CVE-2024-5420 in your systems before they can be exploited. Gain insights from our expert analyses and stay ahead of potential threats. Our user-friendly interface makes it easy to monitor your digital assets, ensuring your data remains secure. Become a member today and take proactive steps towards a safer digital environment.

References:

Solution Advice
  • Regularly update the SEH utnserver Pro/ProMAX/INU-100 to the latest version.
  • Implement input validation to sanitize user inputs for the device description parameter.
  • Use Content Security Policy (CSP) headers to mitigate the risk of XSS attacks.
  • Conduct regular security assessments to identify and remediate vulnerabilities.
  • Educate users about the risks of clicking on unknown links to prevent phishing attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.