Improper UI Layer Restrictions in Conext ComBox by Schneider Electric
CVE-2022-32517

6.5MEDIUM

Key Information:

Vendor
CVE Published:
30 January 2023

Summary

An improper restriction of rendered UI layers or frames vulnerability exists in the Conext ComBox, enabling potential attackers to exploit the system's interface. This flaw may allow malicious actors to manipulate how the application's user interface is presented to users, potentially tricking them into unintended interactions with the application. As the product doesn't enforce necessary restrictions on rendering content from external sources, users may be exposed to a range of security risks that could compromise the integrity and confidentiality of their operations.

Affected Version(s)

Conext™ ComBox All Versions

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.