CVE-2024-3776: Netvision Airpass
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
The parameter used in the login page of Netvision airPASS is not properly filtered for user input. An unauthenticated remote attacker can insert JavaScript code to the parameter for Reflected Cross-site scripting attacks.
Affected products
- Netvision Airpass: version 2.9.0.231006 only
Published 2024-04-15. Last modified 2026-06-17.