{"id":"CVE-2022-24654","title":"Authenticated stored cross-site scripting (XSS) vulnerability in \"Field Server Address\" field in INTELBRAS ATA 200 Firmware 74.19.10.21 allows attackers to inject JavaScript code through a crafted payload.","summary":"Authenticated stored cross-site scripting (XSS) vulnerability in \"Field Server Address\" field in INTELBRAS ATA 200 Firmware 74.19.10.21 allows attackers to inject JavaScript code through a crafted payload.","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"intelbras","product":"ata_200_firmware","affected":["ata_200_firmware = 74.19.10.21"],"published":"2022-08-15","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-24654","references":[{"url":"https://github.com/leonardobg/CVE-2022-24654","label":"cve@mitre.org"},{"url":"https://packetstormsecurity.com/files/168064/Intelbras-ATA-200-Cross-Site-Scripting.html","label":"cve@mitre.org"},{"url":"http://intelbras.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/leonardobg/CVE-2022-24654","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://packetstormsecurity.com/files/168064/Intelbras-ATA-200-Cross-Site-Scripting.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.01185,"epssPercentile":0.66483,"ingestedAt":"2026-07-06T17:03:24.874Z","exploits":{"github":1,"githubRepos":["https://github.com/leonardobg/CVE-2022-24654"],"checkedAt":"2026-09-24T07:52:49.021Z"},"exploitAvailable":true,"slug":"CVE-2022-24654","body":"## Overview\n\nAuthenticated stored cross-site scripting (XSS) vulnerability in \"Field Server Address\" field in INTELBRAS ATA 200 Firmware 74.19.10.21 allows attackers to inject JavaScript code through a crafted payload.\n\n## Affected\n\n- `ata_200_firmware = 74.19.10.21`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":29.7,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":4594,"id":"CVE-2022-24654","ts":1788887193611,"field":"exploit_available","old":"false","new":"true"},{"seq":3477,"id":"CVE-2022-24654","ts":1788886310024,"field":"exploit_available","old":"true","new":"false"},{"seq":2331,"id":"CVE-2022-24654","ts":1788882979547,"field":"exploit_available","old":"false","new":"true"},{"seq":1360,"id":"CVE-2022-24654","ts":1788882392126,"field":"exploit_available","old":"true","new":"false"},{"seq":474,"id":"CVE-2022-24654","ts":1788881827752,"field":"exploit_available","old":"false","new":"true"}]}