PT-2022-25262 · Siemens · Pxg3.W100-2+9
Published
2022-10-11
·
Updated
2023-07-10
·
CVE-2022-40181
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Desigo PXM30-1 versions prior to V02.20.126.11-41
Desigo PXM30.E versions prior to V02.20.126.11-41
Desigo PXM40-1 versions prior to V02.20.126.11-41
Desigo PXM40.E versions prior to V02.20.126.11-41
Desigo PXM50-1 versions prior to V02.20.126.11-41
Desigo PXM50.E versions prior to V02.20.126.11-41
PXG3.W100-1 versions prior to V02.20.126.11-37
PXG3.W100-2 versions prior to V02.20.126.11-41
PXG3.W200-1 versions prior to V02.20.126.11-37
PXG3.W200-2 versions prior to V02.20.126.11-41
Description
The device embedded browser does not prevent interaction with alternative URI schemes when redirected to corresponding resources by web application code. By setting the homepage URI, the favorite URIs, or redirecting embedded browser users via JavaScript code to alternative scheme resources, a remote low privileged attacker can perform a range of attacks against the device, such as read arbitrary files on the filesystem, execute arbitrary JavaScript code in order to steal or manipulate the information on the screen, or trigger denial of service conditions.
Recommendations
For Desigo PXM30-1 versions prior to V02.20.126.11-41, update to version V02.20.126.11-41 or later.
For Desigo PXM30.E versions prior to V02.20.126.11-41, update to version V02.20.126.11-41 or later.
For Desigo PXM40-1 versions prior to V02.20.126.11-41, update to version V02.20.126.11-41 or later.
For Desigo PXM40.E versions prior to V02.20.126.11-41, update to version V02.20.126.11-41 or later.
For Desigo PXM50-1 versions prior to V02.20.126.11-41, update to version V02.20.126.11-41 or later.
For Desigo PXM50.E versions prior to V02.20.126.11-41, update to version V02.20.126.11-41 or later.
For PXG3.W100-1 versions prior to V02.20.126.11-37, update to version V02.20.126.11-37 or later.
For PXG3.W100-2 versions prior to V02.20.126.11-41, update to version V02.20.126.11-41 or later.
For PXG3.W200-1 versions prior to V02.20.126.11-37, update to version V02.20.126.11-37 or later.
For PXG3.W200-2 versions prior to V02.20.126.11-41, update to version V02.20.126.11-41 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Desigo Pxm30-1
Desigo Pxm30.E
Desigo Pxm40-1
Desigo Pxm40.E
Desigo Pxm50-1
Desigo Pxm50.E
Pxg3.W100-1
Pxg3.W100-2
Pxg3.W200-1
Pxg3.W200-2