PT-2022-6691 · Siemens · Spectrum Power 4
Published
2022-02-08
·
Updated
2022-02-18
·
CVE-2022-23312
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Spectrum Power 4 versions prior to V4.70 SP9 Security Patch 1
Description
A Cross-Site Scripting (XSS) vulnerability has been identified in the integrated web application "Online Help" of the affected product. This issue could be exploited if unsuspecting users are tricked into accessing a malicious link, potentially allowing a remote attacker to perform cross-site scripting attacks. The vulnerability is related to the lack of protection of the web page structure.
Recommendations
For versions prior to V4.70 SP9 Security Patch 1, update to V4.70 SP9 Security Patch 1 to resolve the issue. As a temporary workaround, consider restricting access to the "Online Help" web application until the patch is applied. Avoid using links from untrusted sources to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spectrum Power 4