ZeroHour

CVE-2022-36325

CVSS 3.1
4.8 medium
EPSS
<1%p59
Published
()
Modified
Description

Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code and lead to a DOM-based XSS.

Vendors
siemens
Products
scalance m-800 firmware, scalance s615 firmware, scalance sc-600 firmware, scalance sc622-2c firmware, scalance sc632-2c firmware, scalance sc636-2c firmware, scalance sc642-2c firmware, scalance sc646-2c firmware, scalance w700 ieee 802.11ax firmware, scalance w700 ieee 802.11n firmware, scalance w700 ieee 802.11ac firmware, scalance xb-200 firmware
Weakness
CWE-80
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.