PT-2022-4147 · Siemens · Scalance Xm-400+9
Published
2022-08-09
·
Updated
2023-06-27
·
CVE-2022-36325
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SCALANCE M-800 / S615 versions prior to V2.3.1
SCALANCE SC-600 family versions prior to V2.3.1
SCALANCE W-1700 IEEE 802.11ac family versions prior to V2.3.1
SCALANCE W-700 IEEE 802.11ax family versions prior to V2.3.1
SCALANCE W-700 IEEE 802.11n family versions prior to V2.3.1
SCALANCE XB-200 switch family versions prior to V2.3.1
SCALANCE XC-200 switch family versions prior to V2.3.1
SCALANCE XF-200BA switch family versions prior to V2.3.1
SCALANCE XM-400 Family versions prior to V2.3.1
SCALANCE XP-200 switch family versions prior to V2.3.1
SCALANCE XR-300WG switch family versions prior to V2.3.1
SCALANCE XR-500 Family versions prior to V2.3.1
Description
Affected devices do not properly sanitize data introduced by a user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code and lead to a DOM-based XSS. The issue is related to the failure to neutralize script-related HTML tags on the web page.
Recommendations
For SCALANCE M-800 / S615 versions prior to V2.3.1, update to version V2.3.1 or later.
For SCALANCE SC-600 family versions prior to V2.3.1, update to version V2.3.1 or later.
For SCALANCE W-1700 IEEE 802.11ac family versions prior to V2.3.1, update to version V2.3.1 or later.
For SCALANCE W-700 IEEE 802.11ax family versions prior to V2.3.1, update to version V2.3.1 or later.
For SCALANCE W-700 IEEE 802.11n family versions prior to V2.3.1, update to version V2.3.1 or later.
For SCALANCE XB-200 switch family versions prior to V2.3.1, update to version V2.3.1 or later.
For SCALANCE XC-200 switch family versions prior to V2.3.1, update to version V2.3.1 or later.
For SCALANCE XF-200BA switch family versions prior to V2.3.1, update to version V2.3.1 or later.
For SCALANCE XM-400 Family versions prior to V2.3.1, update to version V2.3.1 or later.
For SCALANCE XP-200 switch family versions prior to V2.3.1, update to version V2.3.1 or later.
For SCALANCE XR-300WG switch family versions prior to V2.3.1, update to version V2.3.1 or later.
For SCALANCE XR-500 Family versions prior to V2.3.1, update to version V2.3.1 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Scalance M-800
Scalance S615
Scalance Sc-600
Scalance W-1700
Scalance W-700
Scalance X-200
Scalance Xf-200Ba
Scalance Xm-400
Scalance Xr-300Wg
Scalance Xr-500