PT-2022-6691 · Siemens · Spectrum Power 4

Published

2022-02-08

·

Updated

2022-02-18

·

CVE-2022-23312

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Spectrum Power 4 versions prior to V4.70 SP9 Security Patch 1
Description A Cross-Site Scripting (XSS) vulnerability has been identified in the integrated web application "Online Help" of the affected product. This issue could be exploited if unsuspecting users are tricked into accessing a malicious link, potentially allowing a remote attacker to perform cross-site scripting attacks. The vulnerability is related to the lack of protection of the web page structure.
Recommendations For versions prior to V4.70 SP9 Security Patch 1, update to V4.70 SP9 Security Patch 1 to resolve the issue. As a temporary workaround, consider restricting access to the "Online Help" web application until the patch is applied. Avoid using links from untrusted sources to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03418
CVE-2022-23312

Affected Products

Spectrum Power 4