A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable to stored cross-site scripting (XSS) attacks.
This could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker.
References
Link | Resource |
---|---|
https://cert-portal.siemens.com/productcert/html/ssa-230445.html | Vendor Advisory |
Configurations
History
15 Nov 2024, 22:53
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
References | () https://cert-portal.siemens.com/productcert/html/ssa-230445.html - Vendor Advisory | |
Summary |
|
|
First Time |
Siemens ozw672
Siemens Siemens ozw772 Siemens ozw672 Firmware Siemens ozw772 Firmware |
|
CPE | cpe:2.3:h:siemens:ozw772:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:ozw672_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:siemens:ozw772_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:siemens:ozw672:-:*:*:*:*:*:*:* |
12 Nov 2024, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-12 13:15
Updated : 2024-11-15 22:53
NVD link : CVE-2024-36140
Mitre link : CVE-2024-36140
CVE.ORG link : CVE-2024-36140
JSON object : View
Products Affected
siemens
- ozw672_firmware
- ozw672
- ozw772
- ozw772_firmware
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')