A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable to stored cross-site scripting (XSS) attacks.
This could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker.
References
Link | Resource |
---|---|
https://cert-portal.siemens.com/productcert/html/ssa-230445.html | Vendor Advisory |
Configurations
History
15 Nov 2024, 22:53
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
First Time |
Siemens ozw672 Firmware
Siemens ozw772 Siemens Siemens ozw672 Siemens ozw772 Firmware |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
References | () https://cert-portal.siemens.com/productcert/html/ssa-230445.html - Vendor Advisory | |
CPE | cpe:2.3:h:siemens:ozw672:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:ozw672_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:siemens:ozw772:-:*:*:*:*:*:*:* cpe:2.3:o:siemens:ozw772_firmware:*:*:*:*:*:*:*:* |
12 Nov 2024, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-12 13:15
Updated : 2024-11-15 22:53
NVD link : CVE-2024-36140
Mitre link : CVE-2024-36140
CVE.ORG link : CVE-2024-36140
JSON object : View
Products Affected
siemens
- ozw772_firmware
- ozw672
- ozw672_firmware
- ozw772
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')