Description
A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable to stored cross-site scripting (XSS) attacks.

This could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker.
Published: 2024-11-12
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-35896 A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable to stored cross-site scripting (XSS) attacks. This could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker.
History

Fri, 15 Nov 2024 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Siemens ozw672 Firmware
Siemens ozw772 Firmware
CPEs cpe:2.3:o:siemens:ozw672_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:ozw772_firmware:*:*:*:*:*:*:*:*
Vendors & Products Siemens ozw672 Firmware
Siemens ozw772 Firmware

Tue, 12 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens ozw672
Siemens ozw772
CPEs cpe:2.3:h:siemens:ozw672:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:ozw772:-:*:*:*:*:*:*:*
Vendors & Products Siemens
Siemens ozw672
Siemens ozw772
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 Nov 2024 13:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable to stored cross-site scripting (XSS) attacks. This could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N'}


Subscriptions

Siemens Ozw672 Ozw672 Firmware Ozw772 Ozw772 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2024-11-12T14:35:44.207Z

Reserved: 2024-05-21T11:44:14.682Z

Link: CVE-2024-36140

cve-icon Vulnrichment

Updated: 2024-11-12T14:35:36.264Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-12T13:15:07.957

Modified: 2024-11-15T22:53:26.063

Link: CVE-2024-36140

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses