Cross-Site Scripting Vulnerability in Kieback & Peter DDC Building Controllers
CVE-2026-4293
5.3MEDIUM
What is CVE-2026-4293?
Kieback & Peter DDC building controllers exhibit a cross-site scripting vulnerability that could allow attackers to execute arbitrary JavaScript in the context of the victim’s web browser. If exploited, this can lead to unauthorized actions being performed, user data exposure, or complete takeover of the browser session. It is crucial for users of these controllers to apply recommended security measures to mitigate potential risks associated with this vulnerability.
Affected Version(s)
DDC4002 0 <= 1.12.14
DDC4002e 0 <= 1.23.4
DDC4020e 0 <= 1.23.4
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Maximilian Hildebrand of G DATA Advanced Analytics reported this vulnerability to CISA.
