Impact
The vulnerability stems from improper neutralization of user input during web page generation, allowing attackers to inject malicious scripts that are stored and later executed when a legitimate user views the affected page. Based on the description, it is inferred that the stored XSS flaw can run arbitrary JavaScript in the context of any authenticated or unauthenticated user who accesses the compromised interface, potentially leading to credential theft, session hijacking, or defacement. The weakness aligns with CWE‑79, a classic input validation issue.
Affected Systems
The issue affects the LimRAD NAC product from Limatek System Inc. any installation running a version earlier than 5.5.7.3.9. No other Limatek products or versions are identified as vulnerable.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity, while an EPSS score of less than 1% suggests a low probability of exploitation at the time of assessment. Based on the description, it is inferred that the flaw could be exploited via the web interface that accepts unsanitized user input, enabling a remote attacker to inject script payloads that execute when a victim views the altered content. The risk remains theoretical but non‑negligible for exposed environments.
OpenCVE Enrichment