PatchSiren cyber security CVE debrief
CVE-2024-6558 HMS Industrial Networks CVE debrief
CISA published advisory ICSA-24-193-20 on 2024-07-11 disclosing a stored cross-site scripting (XSS) vulnerability in HMS Industrial Networks Anybus-CompactCom 30 products. The flaw stems from missing input sanitization, allowing attackers to inject and persist HTML/ JavaScript in input fields. When a user subsequently loads the affected page, the browser executes the payload, creating a vector for social engineering. CVSS 3.0 score is 6.3 (Medium). HMS has issued a security advisory and recommends password-protecting web pages, disabling the webserver, network segmentation, or upgrading to Anybus-CompactCom 40 modules.
- Vendor
- HMS Industrial Networks
- Product
- Anybus-CompactCom 30
- CVSS
- MEDIUM 6.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-07-11
- Original CVE updated
- 2024-07-11
- Advisory published
- 2024-07-11
- Advisory updated
- 2024-07-11
Who should care
Industrial control system operators, OT security teams, and asset owners deploying HMS Anybus-CompactCom 30 modules in manufacturing, process control, or building automation environments. Organizations with remote or internet-exposed device management interfaces face elevated risk of social engineering attacks leveraging this stored XSS vector.
Technical summary
The Anybus-CompactCom 30 embedded networking module fails to sanitize user input in web interface fields, permitting stored XSS. Attackers can persist malicious HTML/ JavaScript that executes in victim browsers on subsequent page loads. This enables credential harvesting, session hijacking, or social engineering via manipulated interface content. The vulnerability requires network access to the device web interface and user interaction to trigger payload execution. HMS recommends access controls, webserver disablement, or hardware upgrade to CompactCom 40 as remediation paths.
Defensive priority
medium
Recommended defensive actions
- Apply vendor-provided mitigations: password-protect all webpages served by the Anybus-CompactCom 30 module or disable the webserver if not required
- Consider upgrading to Anybus-CompactCom 40 module as a vendor-supported remediation
- Deploy network segmentation to isolate affected devices behind firewalls, ensuring isolation from corporate networks and blocking unnecessary protocols from unauthorized sources
- Review and implement CISA ICS recommended practices for defense-in-depth strategies
- Monitor for HMS security advisory updates regarding firmware patches or additional mitigations
Evidence notes
CISA CSAF advisory ICSA-24-193-20 confirms stored XSS via lack of input sanitization in Anybus-CompactCom 30. HMS security advisory provides vendor mitigations including password protection, webserver disablement, and product upgrade path to CompactCom 40.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-6558 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-6558
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-6558 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-6558
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-193-20.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-193-20
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.