Cross-Site Scripting Vulnerability in Siemens SCALANCE Series Devices
CVE-2022-40631
6.1MEDIUM
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 11 October 2022
Summary
A cross-site scripting (XSS) vulnerability exists in various Siemens SCALANCE devices, impacting versions prior to V5.5.0 or V5.2.5. If exploited, this vulnerability could allow an attacker to perform session hijacking, compromising user sessions and potentially gaining unauthorized access to sensitive information. It is critical for users of these devices to upgrade to the latest versions to mitigate this risk actively.
Affected Version(s)
SCALANCE X200-4P IRT All versions < V5.5.0
SCALANCE X201-3P IRT All versions < V5.5.0
SCALANCE X201-3P IRT PRO All versions < V5.5.0
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved