Vulnerability in Siemens Desigo PXM and PXG Series Products
CVE-2022-40181
8.3HIGH
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 11 October 2022
What is CVE-2022-40181?
A security flaw exists in various Siemens Desigo PXM and PXG series products where the embedded browser inadequately restricts interactions with alternative URI schemes. This vulnerability allows a remote attacker with low privileges to exploit this weakness by manipulating the homepage or redirecting users through JavaScript. As a result, they could read arbitrary files from the device's filesystem, execute malicious JavaScript that compromises user data, or even trigger denial of service conditions, raising serious concerns for system integrity and data privacy.
Affected Version(s)
Desigo PXM30-1 All versions < V02.20.126.11-41
Desigo PXM30.E All versions < V02.20.126.11-41
Desigo PXM40-1 All versions < V02.20.126.11-41