Vulnerability Description
Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code and lead to a DOM-based XSS.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Scalance M-800 Firmware | All versions |
| Siemens | Scalance M-800 | - |
| Siemens | Scalance S615 Firmware | All versions |
| Siemens | Scalance S615 | - |
| Siemens | Scalance Sc-600 Firmware | < 2.3.1 |
| Siemens | Scalance Sc-600 | - |
| Siemens | Scalance Sc622-2C Firmware | < 2.3.1 |
| Siemens | Scalance Sc622-2C | - |
| Siemens | Scalance Sc632-2C Firmware | < 2.3.1 |
| Siemens | Scalance Sc632-2C | - |
| Siemens | Scalance Sc636-2C Firmware | < 2.3.1 |
| Siemens | Scalance Sc636-2C | - |
| Siemens | Scalance Sc642-2C Firmware | < 2.3.1 |
| Siemens | Scalance Sc642-2C | - |
| Siemens | Scalance Sc646-2C Firmware | < 2.3.1 |
| Siemens | Scalance Sc646-2C | - |
| Siemens | Scalance W700 Ieee 802.11Ax Firmware | All versions |
| Siemens | Scalance W700 Ieee 802.11Ax | - |
| Siemens | Scalance W700 Ieee 802.11N Firmware | All versions |
| Siemens | Scalance W700 Ieee 802.11N | - |
Related Weaknesses (CWE)
References
- https://cert-portal.siemens.com/productcert/html/ssa-019200.html
- https://cert-portal.siemens.com/productcert/html/ssa-710008.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-710008.pdfMitigationVendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-710008.pdfMitigationVendor Advisory
FAQ
What is CVE-2022-36325?
CVE-2022-36325 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code a...
How severe is CVE-2022-36325?
CVE-2022-36325 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-36325?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens Scalance M-800 Firmware, Siemens Scalance M-800, Siemens Scalance S615 Firmware, Siemens Scalance S615, Siemens Scalance Sc-600 Firmware.