CVE-2022-36325

Published Aug 10, 2022

Last updated 6 months ago

Overview

Description
Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code and lead to a DOM-based XSS.
Source
productcert@siemens.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
4.8
Impact score
2.7
Exploitability score
1.7
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Severity
MEDIUM

Weaknesses

productcert@siemens.com
CWE-80
nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Configurations