Vulnerability Description
An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device ID field under Inventory Management to achieve Remote Code Execution and privilege escalation..
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xfinity | Comcast Defined Technologies Microeisbss | <= 2021 |
Related Weaknesses (CWE)
References
- https://my.xfinity.com/vulnerabilityreportNot Applicable
- https://pensecure.medium.com/cve-2022-45938-f4c0d441da6fExploitPress/Media Coverage
- https://my.xfinity.com/vulnerabilityreportNot Applicable
- https://pensecure.medium.com/cve-2022-45938-f4c0d441da6fExploitPress/Media Coverage
FAQ
What is CVE-2022-45938?
CVE-2022-45938 is a vulnerability with a CVSS score of 9.0 (CRITICAL). An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device ID field under Inventory Management to achieve Remote Code E...
How severe is CVE-2022-45938?
CVE-2022-45938 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-45938?
Check the references section above for vendor advisories and patch information. Affected products include: Xfinity Comcast Defined Technologies Microeisbss.