Vulnerability in Siemens Desigo PXM and PXG Series Products
CVE-2022-40181
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 11 October 2022
Summary
A security flaw exists in various Siemens Desigo PXM and PXG series products where the embedded browser inadequately restricts interactions with alternative URI schemes. This vulnerability allows a remote attacker with low privileges to exploit this weakness by manipulating the homepage or redirecting users through JavaScript. As a result, they could read arbitrary files from the device's filesystem, execute malicious JavaScript that compromises user data, or even trigger denial of service conditions, raising serious concerns for system integrity and data privacy.
Affected Version(s)
Desigo PXM30-1 All versions < V02.20.126.11-41
Desigo PXM30.E All versions < V02.20.126.11-41
Desigo PXM40-1 All versions < V02.20.126.11-41
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved