MEDIUM · 6.8

CVE-2022-36325

Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code a...

Vulnerability Description

Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code and lead to a DOM-based XSS.

CVSS Score

6.8

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
SiemensScalance M-800 FirmwareAll versions
SiemensScalance M-800-
SiemensScalance S615 FirmwareAll versions
SiemensScalance S615-
SiemensScalance Sc-600 Firmware< 2.3.1
SiemensScalance Sc-600-
SiemensScalance Sc622-2C Firmware< 2.3.1
SiemensScalance Sc622-2C-
SiemensScalance Sc632-2C Firmware< 2.3.1
SiemensScalance Sc632-2C-
SiemensScalance Sc636-2C Firmware< 2.3.1
SiemensScalance Sc636-2C-
SiemensScalance Sc642-2C Firmware< 2.3.1
SiemensScalance Sc642-2C-
SiemensScalance Sc646-2C Firmware< 2.3.1
SiemensScalance Sc646-2C-
SiemensScalance W700 Ieee 802.11Ax FirmwareAll versions
SiemensScalance W700 Ieee 802.11Ax-
SiemensScalance W700 Ieee 802.11N FirmwareAll versions
SiemensScalance W700 Ieee 802.11N-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-36325?

CVE-2022-36325 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code a...

How severe is CVE-2022-36325?

CVE-2022-36325 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-36325?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Scalance M-800 Firmware, Siemens Scalance M-800, Siemens Scalance S615 Firmware, Siemens Scalance S615, Siemens Scalance Sc-600 Firmware.