MEDIUM · 5.4

CVE-2022-42786

Multiple W&T Products of the ComServer Series are prone to an XSS attack. An authenticated remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into the title of th...

Vulnerability Description

Multiple W&T Products of the ComServer Series are prone to an XSS attack. An authenticated remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into the title of the configuration webpage

CVSS Score

5.4

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
WutAt-Modem-Emulator Firmware< 1.48
WutAt-Modem-Emulator-
WutCom-Server \+\+ Firmware< 1.48
WutCom-Server \+\+-
WutCom-Server 20Ma Firmware< 1.48
WutCom-Server 20Ma-
WutCom-Server Highspeed 100Basefx Firmware< 1.76
WutCom-Server Highspeed 100Basefx-
WutCom-Server Highspeed 100Baselx Firmware< 1.76
WutCom-Server Highspeed 100Baselx-
WutCom-Server Highspeed 19\" 1Port Firmware< 1.76
WutCom-Server Highspeed 19\" 1Port-
WutCom-Server Highspeed 19\" 4Port Firmware< 1.76
WutCom-Server Highspeed 19\" 4Port-
WutCom-Server Highspeed Compact Firmware< 1.76
WutCom-Server Highspeed Compact-
WutCom-Server Highspeed Industry Firmware< 1.76
WutCom-Server Highspeed Industry-
WutCom-Server Highspeed Isolated Firmware< 1.76
WutCom-Server Highspeed Isolated-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-42786?

CVE-2022-42786 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Multiple W&T Products of the ComServer Series are prone to an XSS attack. An authenticated remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into the title of th...

How severe is CVE-2022-42786?

CVE-2022-42786 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-42786?

Check the references section above for vendor advisories and patch information. Affected products include: Wut At-Modem-Emulator Firmware, Wut At-Modem-Emulator, Wut Com-Server \+\+ Firmware, Wut Com-Server \+\+, Wut Com-Server 20Ma Firmware.