High severity7.6NVD Advisory· Published Apr 18, 2023· Updated Jun 17, 2026
CVE-2022-43376
CVE-2022-43376
Description
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause code and session manipulation when malicious code is inserted into the browser.
Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0
and prior)
Affected products
8- cpe:2.3:o:schneider-electric:netbotz_355_firmware:*:*:*:*:*:*:*:*Range: >=4.0.0,<=4.7.0
- cpe:2.3:o:schneider-electric:netbotz_450_firmware:*:*:*:*:*:*:*:*Range: >=4.0.0,<=4.7.0
- cpe:2.3:o:schneider-electric:netbotz_455_firmware:*:*:*:*:*:*:*:*Range: >=4.0.0,<=4.7.0
- cpe:2.3:o:schneider-electric:netbotz_550_firmware:*:*:*:*:*:*:*:*Range: >=4.0.0,<=4.7.0
- cpe:2.3:o:schneider-electric:netbotz_570_firmware:*:*:*:*:*:*:*:*Range: >=4.0.0,<=4.7.0
- Range: <=V4.7.0
- Schneider Electric/NetBotz 4 - 355/450/455/550/570v5Range: V4.7.0 and prior
Patches
Vulnerability mechanics
References
1- download.schneider-electric.com/filesnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.