Carrier Corporation i-VU Cross-site Scripting (CVE-2024-5540)

medium Tenable OT Security Plugin ID 505506

Synopsis

The remote OT asset is affected by a vulnerability.

Description

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in Automated Logic WebCTRL and Carrier i-Vu Building Automation System products in versions older than 8.0. Untrusted data is included in web pages without proper validation, allowing attackers to execute malicious scripts in the user's browser.

This plugin only works with Tenable.ot.
Please visit https://www.tenable.com/products/tenable-ot for more information.

Solution

Upgrade to Automated Logic WebCTRL or Carrier i-Vu version 8.0 or later. Versions 7.0, 6.5, and 6.1 are no longer supported.

See Also

http://www.nessus.org/u?4bedf100

Plugin Details

Severity: Medium

ID: 505506

File Name: tenable_ot_carriercorporation_CVE-2024-5540.nasl

Version: 1.1

Type: Remote

Family: Tenable.ot

Published: 6/23/2026

Updated: 6/23/2026

Supported Sensors: Tenable OT Security

Risk Information

VPR

Risk Factor: Low

Score: 3.0

CVSS v3

Risk Factor: Medium

Base Score: 6.1

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Threat Score: 2.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/a:automatedlogic:i-vu

Required KB Items: Tenable.ot/CarrierCorporation

Patch Publication Date: 11/26/2025

Vulnerability Publication Date: 11/26/2025

Reference Information

CVE: CVE-2024-5540

CWE: 79