A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable to stored cross-site scripting (XSS) attacks. This could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker.
History

Fri, 15 Nov 2024 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Siemens ozw672 Firmware
Siemens ozw772 Firmware
CPEs cpe:2.3:o:siemens:ozw672_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:ozw772_firmware:*:*:*:*:*:*:*:*
Vendors & Products Siemens ozw672 Firmware
Siemens ozw772 Firmware

Tue, 12 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens ozw672
Siemens ozw772
CPEs cpe:2.3:h:siemens:ozw672:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:ozw772:-:*:*:*:*:*:*:*
Vendors & Products Siemens
Siemens ozw672
Siemens ozw772
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 Nov 2024 13:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable to stored cross-site scripting (XSS) attacks. This could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker.
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published: 2024-11-12T12:49:32.130Z

Updated: 2024-11-12T14:35:44.207Z

Reserved: 2024-05-21T11:44:14.682Z

Link: CVE-2024-36140

cve-icon Vulnrichment

Updated: 2024-11-12T14:35:36.264Z

cve-icon NVD

Status : Analyzed

Published: 2024-11-12T13:15:07.957

Modified: 2024-11-15T22:53:26.063

Link: CVE-2024-36140

cve-icon Redhat

No data.