Impact
A cross‑site scripting flaw in the Builder Component of Pilz PASvisu before 1.14.1 permits a local unauthenticated attacker to inject malicious JavaScript that can take full control of the device. This variant of CWE‑79 can be used to execute arbitrary commands or exfiltrate data, effectively giving the attacker complete device control.
Affected Systems
Pilz PASvisu (all releases prior to 1.14.1) and Pilz PMI v8xx (affected versions not specified, but any unpatched installation is potentially vulnerable).
Risk and Exploitability
The CVSS score of 7.8 indicates a high level of severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local; an attacker would need access to the device’s local network or console to reach the Builder Component and inject the malicious script.
OpenCVE Enrichment