Lucene search

K
nvd[email protected]NVD:CVE-2022-40631
HistoryOct 11, 2022 - 11:15 a.m.

CVE-2022-40631

2022-10-1111:15:10
CWE-79
web.nvd.nist.gov
4
cross-site scripting
scalance
vulnerability
session hijacking

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

31.3%

A vulnerability has been identified in SCALANCE X200-4P IRT (All versions < V5.5.0), SCALANCE X201-3P IRT (All versions < V5.5.0), SCALANCE X201-3P IRT PRO (All versions < V5.5.0), SCALANCE X202-2IRT (All versions < V5.5.0), SCALANCE X202-2P IRT (All versions < V5.5.0), SCALANCE X202-2P IRT PRO (All versions < V5.5.0), SCALANCE X204-2 (All versions < V5.2.5), SCALANCE X204-2FM (All versions < V5.2.5), SCALANCE X204-2LD (All versions < V5.2.5), SCALANCE X204-2LD TS (All versions < V5.2.5), SCALANCE X204-2TS (All versions < V5.2.5), SCALANCE X204IRT (All versions < V5.5.0), SCALANCE X204IRT PRO (All versions < V5.5.0), SCALANCE X206-1 (All versions < V5.2.5), SCALANCE X206-1LD (All versions < V5.2.5), SCALANCE X208 (All versions < V5.2.5), SCALANCE X208PRO (All versions < V5.2.5), SCALANCE X212-2 (All versions < V5.2.5), SCALANCE X212-2LD (All versions < V5.2.5), SCALANCE X216 (All versions < V5.2.5), SCALANCE X224 (All versions < V5.2.5), SCALANCE XF201-3P IRT (All versions < V5.5.0), SCALANCE XF202-2P IRT (All versions < V5.5.0), SCALANCE XF204 (All versions < V5.2.5), SCALANCE XF204-2 (All versions < V5.2.5), SCALANCE XF204-2BA IRT (All versions < V5.5.0), SCALANCE XF204IRT (All versions < V5.5.0), SCALANCE XF206-1 (All versions < V5.2.5), SCALANCE XF208 (All versions < V5.2.5), SIPLUS NET SCALANCE X202-2P IRT (All versions < V5.5.0). There is a cross-site scripting vulnerability on the affected devices, that if used by a threat actor, it could result in session hijacking.

Affected configurations

Nvd
Node
siemensscalance_x200-4p_irt_firmwareRange<5.5.0
AND
siemensscalance_x200-4p_irtMatch-
Node
siemensscalance_x201-3p_irt_firmwareRange<5.5.0
AND
siemensscalance_x201-3p_irtMatch-
Node
siemensscalance_x201-3p_irt_pro_firmwareRange<5.5.0
AND
siemensscalance_x201-3p_irt_proMatch-
Node
siemensscalance_x202-2irt_firmwareRange<5.5.0
AND
siemensscalance_x202-2irtMatch-
Node
siemensscalance_x202-2p_irt_firmwareRange<5.5.0
AND
siemensscalance_x202-2p_irtMatch-
Node
siemensscalance_x202-2p_irt_pro_firmwareRange<5.5.0
AND
siemensscalance_x202-2p_irt_proMatch-
Node
siemensscalance_x204-2_firmwareRange<5.2.5
AND
siemensscalance_x204-2Match-
Node
siemensscalance_x204-2fm_firmwareRange<5.2.5
AND
siemensscalance_x204-2fmMatch-
Node
siemensscalance_x204-2ld_firmwareRange<5.2.5
AND
siemensscalance_x204-2ldMatch-
Node
siemensscalance_x204-2ld_ts_firmwareRange<5.2.5
AND
siemensscalance_x204-2ld_tsMatch-
Node
siemensscalance_x204-2ts_firmwareRange<5.2.5
AND
siemensscalance_x204-2tsMatch-
Node
siemensscalance_x204irt_firmwareRange<5.5.0
AND
siemensscalance_x204irtMatch-
Node
siemensscalance_x204irt_pro_firmwareRange<5.5.0
AND
siemensscalance_x204irt_proMatch-
Node
siemensscalance_x206-1_firmwareRange<5.2.5
AND
siemensscalance_x206-1Match-
Node
siemensscalance_x206-1ld_firmwareRange<5.2.5
AND
siemensscalance_x206-1ldMatch-
Node
siemensscalance_x208_firmwareRange<5.2.5
AND
siemensscalance_x208Match-
Node
siemensscalance_x208pro_firmwareRange<5.2.5
AND
siemensscalance_x208proMatch-
Node
siemensscalance_x212-2_firmwareRange<5.2.5
AND
siemensscalance_x212-2Match-
Node
siemensscalance_x212-2ld_firmwareRange<5.2.5
AND
siemensscalance_x212-2ldMatch-
Node
siemensscalance_x216_firmwareRange<5.2.5
AND
siemensscalance_x216Match-
Node
siemensscalance_x224_firmwareRange<5.2.5
AND
siemensscalance_x224Match-
Node
siemensscalance_xf201-3p_irt_firmwareRange<5.5.0
AND
siemensscalance_xf201-3p_irtMatch-
Node
siemensscalance_xf202-2p_irt_firmwareRange<5.5.0
AND
siemensscalance_xf202-2p_irtMatch-
Node
siemensscalance_xf204_firmwareRange<5.2.5
AND
siemensscalance_xf204Match-
Node
siemensscalance_xf204-2_firmwareRange<5.2.5
AND
siemensscalance_xf204-2Match-
Node
siemensscalance_xf204-2ba_irt_firmwareRange<5.5.0
AND
siemensscalance_xf204-2ba_irtMatch-
Node
siemensscalance_xf204irt_firmwareRange<5.5.0
AND
siemensscalance_xf204irtMatch-
Node
siemensscalance_xf206-1_firmwareRange<5.2.5
AND
siemensscalance_xf206-1Match-
Node
siemensscalance_xf208_firmwareRange<5.2.5
AND
siemensscalance_xf208Match-
Node
siemenssiplus_net_scalance_x202-2p_irt_firmwareRange<5.5.0
AND
siemenssiplus_net_scalance_x202-2p_irtMatch-
VendorProductVersionCPE
siemensscalance_x200-4p_irt_firmware*cpe:2.3:o:siemens:scalance_x200-4p_irt_firmware:*:*:*:*:*:*:*:*
siemensscalance_x200-4p_irt-cpe:2.3:h:siemens:scalance_x200-4p_irt:-:*:*:*:*:*:*:*
siemensscalance_x201-3p_irt_firmware*cpe:2.3:o:siemens:scalance_x201-3p_irt_firmware:*:*:*:*:*:*:*:*
siemensscalance_x201-3p_irt-cpe:2.3:h:siemens:scalance_x201-3p_irt:-:*:*:*:*:*:*:*
siemensscalance_x201-3p_irt_pro_firmware*cpe:2.3:o:siemens:scalance_x201-3p_irt_pro_firmware:*:*:*:*:*:*:*:*
siemensscalance_x201-3p_irt_pro-cpe:2.3:h:siemens:scalance_x201-3p_irt_pro:-:*:*:*:*:*:*:*
siemensscalance_x202-2irt_firmware*cpe:2.3:o:siemens:scalance_x202-2irt_firmware:*:*:*:*:*:*:*:*
siemensscalance_x202-2irt-cpe:2.3:h:siemens:scalance_x202-2irt:-:*:*:*:*:*:*:*
siemensscalance_x202-2p_irt_firmware*cpe:2.3:o:siemens:scalance_x202-2p_irt_firmware:*:*:*:*:*:*:*:*
siemensscalance_x202-2p_irt-cpe:2.3:h:siemens:scalance_x202-2p_irt:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 601

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

31.3%

Related for NVD:CVE-2022-40631