Lucene search

K
cveSiemensCVE-2022-46350
HistoryDec 13, 2022 - 4:15 p.m.

CVE-2022-46350

2022-12-1316:15:25
CWE-80
CWE-79
siemens
web.nvd.nist.gov
30
cve-2022-46350
scalance x204rna
scalance x204rna eec
hsr
prp
cross-site scripting
xss
security vulnerability

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

31.5%

A vulnerability has been identified in SCALANCE X204RNA (HSR) (All versions < V3.2.7), SCALANCE X204RNA (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (HSR) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP) (All versions < V3.2.7), SCALANCE X204RNA EEC (PRP/HSR) (All versions < V3.2.7). The integrated web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. This can be used by an attacker to trigger a malicious request on the affected device.

Affected configurations

Nvd
Node
siemens6gk5204-0ba00-2mb2Match-
AND
siemens6gk5204-0ba00-2mb2_firmwareRange<3.2.7
Node
siemens6gk5204-0ba00-2kb2Match-
AND
siemens6gk5204-0ba00-2kb2_firmwareRange<3.2.7
Node
siemens6gk5204-0bs00-2na3Match-
AND
siemens6gk5204-0bs00-2na3_firmwareRange<3.2.7
Node
siemens6gk5204-0bs00-3la3Match-
AND
siemens6gk5204-0bs00-3la3_firmwareRange<3.2.7
Node
siemens6gk5204-0bs00-3pa3Match-
AND
siemens6gk5204-0bs00-3pa3_firmwareRange<3.2.7
VendorProductVersionCPE
siemens6gk5204-0ba00-2mb2-cpe:2.3:h:siemens:6gk5204-0ba00-2mb2:-:*:*:*:*:*:*:*
siemens6gk5204-0ba00-2mb2_firmware*cpe:2.3:o:siemens:6gk5204-0ba00-2mb2_firmware:*:*:*:*:*:*:*:*
siemens6gk5204-0ba00-2kb2-cpe:2.3:h:siemens:6gk5204-0ba00-2kb2:-:*:*:*:*:*:*:*
siemens6gk5204-0ba00-2kb2_firmware*cpe:2.3:o:siemens:6gk5204-0ba00-2kb2_firmware:*:*:*:*:*:*:*:*
siemens6gk5204-0bs00-2na3-cpe:2.3:h:siemens:6gk5204-0bs00-2na3:-:*:*:*:*:*:*:*
siemens6gk5204-0bs00-2na3_firmware*cpe:2.3:o:siemens:6gk5204-0bs00-2na3_firmware:*:*:*:*:*:*:*:*
siemens6gk5204-0bs00-3la3-cpe:2.3:h:siemens:6gk5204-0bs00-3la3:-:*:*:*:*:*:*:*
siemens6gk5204-0bs00-3la3_firmware*cpe:2.3:o:siemens:6gk5204-0bs00-3la3_firmware:*:*:*:*:*:*:*:*
siemens6gk5204-0bs00-3pa3-cpe:2.3:h:siemens:6gk5204-0bs00-3pa3:-:*:*:*:*:*:*:*
siemens6gk5204-0bs00-3pa3_firmware*cpe:2.3:o:siemens:6gk5204-0bs00-3pa3_firmware:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Siemens",
    "product": "SCALANCE X204RNA (HSR)",
    "versions": [
      {
        "version": "All versions < V3.2.7",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Siemens",
    "product": "SCALANCE X204RNA (PRP)",
    "versions": [
      {
        "version": "All versions < V3.2.7",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Siemens",
    "product": "SCALANCE X204RNA EEC (HSR)",
    "versions": [
      {
        "version": "All versions < V3.2.7",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Siemens",
    "product": "SCALANCE X204RNA EEC (PRP)",
    "versions": [
      {
        "version": "All versions < V3.2.7",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Siemens",
    "product": "SCALANCE X204RNA EEC (PRP/HSR)",
    "versions": [
      {
        "version": "All versions < V3.2.7",
        "status": "affected"
      }
    ]
  }
]

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

31.5%

Related for CVE-2022-46350