Cross-Site Scripting Vulnerability in Siemens SCALANCE Series Devices
CVE-2022-40631

6.1MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
11 October 2022

Summary

A cross-site scripting (XSS) vulnerability exists in various Siemens SCALANCE devices, impacting versions prior to V5.5.0 or V5.2.5. If exploited, this vulnerability could allow an attacker to perform session hijacking, compromising user sessions and potentially gaining unauthorized access to sensitive information. It is critical for users of these devices to upgrade to the latest versions to mitigate this risk actively.

Affected Version(s)

SCALANCE X200-4P IRT All versions < V5.5.0

SCALANCE X201-3P IRT All versions < V5.5.0

SCALANCE X201-3P IRT PRO All versions < V5.5.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.