VYPR
Unrated severityNVD Advisory· Published Oct 11, 2022· Updated Aug 3, 2024

CVE-2022-40178

CVE-2022-40178

Description

A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41). Improper Neutralization of Input During Web Page Generation exists in the “Import Files“ functionality of the “Operation” web application, due to the missing validation of the titles of files included in the input package. By uploading a specifically crafted graphics package, a remote low-privileged attacker can execute arbitrary JavaScript code.

Affected products

10
  • Siemens/Desigo PXM30-1v5
    Range: All versions < V02.20.126.11-41
  • All versions < V02.20.126.11-41+ 2 more
    • (no CPE)range: All versions < V02.20.126.11-41
    • (no CPE)range: All versions < V02.20.126.11-41
    • (no CPE)range: All versions < V02.20.126.11-41
  • Siemens/Desigo PXM40-1v5
    Range: All versions < V02.20.126.11-41
  • Siemens/Desigo PXM50-1v5
    Range: All versions < V02.20.126.11-41
  • Siemens/PXG3.W100-1v5
    Range: All versions < V02.20.126.11-37
  • Siemens/PXG3.W100-2v5
    Range: All versions < V02.20.126.11-41
  • Siemens/PXG3.W200-1v5
    Range: All versions < V02.20.126.11-37
  • Siemens/PXG3.W200-2v5
    Range: All versions < V02.20.126.11-41

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.