PT-2022-3534 · Schneider Electric · Conext Combox
Published
2022-06-14
·
Updated
2023-02-07
·
CVE-2022-32517
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
Conext ComBox versions all
Description
The issue is related to improper restriction of rendered UI layers or frames in the user interface, which could allow a remote adversary to affect data integrity by tricking the user into interacting with the application in an unintended way. This is due to the product not implementing restrictions on rendering within frames on external addresses.
Recommendations
For Conext ComBox versions all, consider restricting the ability to render within frames on external addresses to minimize the risk of exploitation. As a temporary workaround, restrict access to external addresses until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Conext Combox