CVE-2022-3073

Quanos "SCHEMA ST4" example web templates in version Bootstrap 2019 v2/2021 v1/2022 v1/2022 SP1 v1 or below are prone to JavaScript injection allowing a remote attacker to hijack existing sessions to e.g. other web services in the same environment or execute scripts in the users browser environment. The affected script is '*-schema.js'.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:weidmueller:19_iot_md01_lan_h4_s0011_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:weidmueller:19_iot_md01_lan_h4_s0011:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:weidmueller:fp_iot_md01_4eu_s2_00000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:weidmueller:fp_iot_md01_4eu_s2_00000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:weidmueller:fp_iot_md01_lan_s2_00000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:weidmueller:fp_iot_md01_lan_s2_00000:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:weidmueller:fp_iot_md01_lan_s2_00011_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:weidmueller:fp_iot_md01_lan_s2_00011:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:weidmueller:fp_iot_md02_4eu_s3_00000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:weidmueller:fp_iot_md02_4eu_s3_00000:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:weidmueller:iot-gw30_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:weidmueller:iot-gw30:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:weidmueller:iot-gw30-4g-eu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:weidmueller:iot-gw30-4g-eu:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:weidmueller:uc20-wl2000-ac_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:weidmueller:uc20-wl2000-ac:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:weidmueller:uc20-wl2000-iot_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:weidmueller:uc20-wl2000-iot:-:*:*:*:*:*:*:*

History

21 Nov 2024, 07:18

Type Values Removed Values Added
References () https://cert.vde.com/de/advisories/VDE-2022-056/ - Third Party Advisory () https://cert.vde.com/de/advisories/VDE-2022-056/ - Third Party Advisory

Information

Published : 2022-12-14 09:15

Updated : 2024-11-21 07:18


NVD link : CVE-2022-3073

Mitre link : CVE-2022-3073

CVE.ORG link : CVE-2022-3073


JSON object : View

Products Affected

weidmueller

  • uc20-wl2000-iot
  • fp_iot_md01_lan_s2_00011_firmware
  • fp_iot_md01_4eu_s2_00000_firmware
  • fp_iot_md01_lan_s2_00011
  • uc20-wl2000-ac
  • fp_iot_md02_4eu_s3_00000_firmware
  • 19_iot_md01_lan_h4_s0011_firmware
  • fp_iot_md02_4eu_s3_00000
  • iot-gw30
  • iot-gw30-4g-eu_firmware
  • 19_iot_md01_lan_h4_s0011
  • uc20-wl2000-iot_firmware
  • fp_iot_md01_4eu_s2_00000
  • fp_iot_md01_lan_s2_00000_firmware
  • uc20-wl2000-ac_firmware
  • fp_iot_md01_lan_s2_00000
  • iot-gw30_firmware
  • iot-gw30-4g-eu
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')