Vulnerability Description
A cross-site scripting (XSS) vulnerability exists in all current versions of Digital Alert Systems DASDEC software via the Host Header in undisclosed pages after login.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Digitalalertsystems | Dasdec Ii Firmware | - |
| Digitalalertsystems | Dasdec Ii | - |
| Digitalalertsystems | One-Net Se Firmware | - |
| Digitalalertsystems | One-Net Se | - |
| Digitalalertsystems | Dasdec I Firmware | - |
| Digitalalertsystems | Dasdec I | - |
| Digitalalertsystems | One-Net Firmware | - |
| Digitalalertsystems | One-Net | - |
| Digitalalertsystems | Dasdec Iii Firmware | - |
| Digitalalertsystems | Dasdec Iii | - |
Related Weaknesses (CWE)
References
- https://www.digitalalertsystems.com/security-advisoryVendor Advisory
- https://www.digitalalertsystems.com/security-advisoryVendor Advisory
FAQ
What is CVE-2022-40204?
CVE-2022-40204 is a vulnerability with a CVSS score of 4.1 (MEDIUM). A cross-site scripting (XSS) vulnerability exists in all current versions of Digital Alert Systems DASDEC software via the Host Header in undisclosed pages after login.
How severe is CVE-2022-40204?
CVE-2022-40204 has been rated MEDIUM with a CVSS base score of 4.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-40204?
Check the references section above for vendor advisories and patch information. Affected products include: Digitalalertsystems Dasdec Ii Firmware, Digitalalertsystems Dasdec Ii, Digitalalertsystems One-Net Se Firmware, Digitalalertsystems One-Net Se, Digitalalertsystems Dasdec I Firmware.