Cross-Site Scripting Vulnerability in SCALANCE X302 and X308 Series by Siemens
CVE-2022-25756
6.1MEDIUM
Key Information:
- Vendor
Siemens
- Status
- Vendor
- CVE Published:
- 12 April 2022
What is CVE-2022-25756?
A vulnerability in the SCALANCE X302 and X308 series from Siemens raises concerns regarding the integrated web server, which may allow for Cross-Site Scripting (XSS) attacks. Attackers could exploit this vulnerability by tricking users into accessing malicious links, enabling them to execute harmful requests on affected devices. The extensive range of impacted products calls for immediate attention to safeguard network infrastructure and mitigate potential security risks.
Affected Version(s)
SCALANCE X302-7 EEC (230V, coated) All versions < V4.1.4
SCALANCE X302-7 EEC (230V) All versions < V4.1.4
SCALANCE X302-7 EEC (24V, coated) All versions < V4.1.4