VYPR
Unrated severityNVD Advisory· Published Oct 11, 2022· Updated Aug 3, 2024

CVE-2022-40181

CVE-2022-40181

Description

A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41). The device embedded browser does not prevent interaction with alternative URI schemes when redirected to corresponding resources by web application code. By setting the homepage URI, the favorite URIs, or redirecting embedded browser users via JavaScript code to alternative scheme resources, a remote low privileged attacker can perform a range of attacks against the device, such as read arbitrary files on the filesystem, execute arbitrary JavaScript code in order to steal or manipulate the information on the screen, or trigger denial of service conditions.

Affected products

10
  • Siemens/Desigo PXM30-1v5
    Range: All versions < V02.20.126.11-41
  • All versions < V02.20.126.11-41+ 2 more
    • (no CPE)range: All versions < V02.20.126.11-41
    • (no CPE)range: All versions < V02.20.126.11-41
    • (no CPE)range: All versions < V02.20.126.11-41
  • Siemens/Desigo PXM40-1v5
    Range: All versions < V02.20.126.11-41
  • Siemens/Desigo PXM50-1v5
    Range: All versions < V02.20.126.11-41
  • Siemens/PXG3.W100-1v5
    Range: All versions < V02.20.126.11-37
  • Siemens/PXG3.W100-2v5
    Range: All versions < V02.20.126.11-41
  • Siemens/PXG3.W200-1v5
    Range: All versions < V02.20.126.11-37
  • Siemens/PXG3.W200-2v5
    Range: All versions < V02.20.126.11-41

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.