A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable to stored cross-site scripting (XSS) attacks.
This could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker.
Metrics
Affected Vendors & Products
References
History
Fri, 15 Nov 2024 23:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Siemens ozw672 Firmware
Siemens ozw772 Firmware |
|
CPEs | cpe:2.3:o:siemens:ozw672_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:siemens:ozw772_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Siemens ozw672 Firmware
Siemens ozw772 Firmware |
Tue, 12 Nov 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Siemens
Siemens ozw672 Siemens ozw772 |
|
CPEs | cpe:2.3:h:siemens:ozw672:-:*:*:*:*:*:*:* cpe:2.3:h:siemens:ozw772:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Siemens
Siemens ozw672 Siemens ozw772 |
|
Metrics |
ssvc
|
Tue, 12 Nov 2024 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable to stored cross-site scripting (XSS) attacks. This could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker. | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: siemens
Published: 2024-11-12T12:49:32.130Z
Updated: 2024-11-12T14:35:44.207Z
Reserved: 2024-05-21T11:44:14.682Z
Link: CVE-2024-36140
Vulnrichment
Updated: 2024-11-12T14:35:36.264Z
NVD
Status : Analyzed
Published: 2024-11-12T13:15:07.957
Modified: 2024-11-15T22:53:26.063
Link: CVE-2024-36140
Redhat
No data.