Cross-Site Scripting Vulnerability in SCALANCE X302 and X308 Series by Siemens
CVE-2022-25756

6.1MEDIUM

Summary

A vulnerability in the SCALANCE X302 and X308 series from Siemens raises concerns regarding the integrated web server, which may allow for Cross-Site Scripting (XSS) attacks. Attackers could exploit this vulnerability by tricking users into accessing malicious links, enabling them to execute harmful requests on affected devices. The extensive range of impacted products calls for immediate attention to safeguard network infrastructure and mitigate potential security risks.

Affected Version(s)

SCALANCE X302-7 EEC (230V, coated) All versions < V4.1.4

SCALANCE X302-7 EEC (230V) All versions < V4.1.4

SCALANCE X302-7 EEC (24V, coated) All versions < V4.1.4

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.