CVE-2022-40178
Summary
| CVE | CVE-2022-40178 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-11 11:15:00 UTC |
| Updated | 2022-10-12 17:17:00 UTC |
| Description | A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41). Improper Neutralization of Input During Web Page Generation exists in the “Import Files“ functionality of the “Operation” web application, due to the missing validation of the titles of files included in the input package. By uploading a specifically crafted graphics package, a remote low-privileged attacker can execute arbitrary JavaScript code. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Siemens | Desigo Pxm30-1 | - | All | All | All |
| Operating System | Siemens | Desigo Pxm30-1 Firmware | All | All | All | All |
| Hardware | Siemens | Desigo Pxm30.e | - | All | All | All |
| Operating System | Siemens | Desigo Pxm30.e Firmware | All | All | All | All |
| Hardware | Siemens | Desigo Pxm40-1 | - | All | All | All |
| Operating System | Siemens | Desigo Pxm40-1 Firmware | All | All | All | All |
| Hardware | Siemens | Desigo Pxm40.e | - | All | All | All |
| Operating System | Siemens | Desigo Pxm40.e Firmware | All | All | All | All |
| Hardware | Siemens | Desigo Pxm50-1 | - | All | All | All |
| Operating System | Siemens | Desigo Pxm50-1 Firmware | All | All | All | All |
| Hardware | Siemens | Desigo Pxm50.e | - | All | All | All |
| Operating System | Siemens | Desigo Pxm50.e Firmware | All | All | All | All |
| Hardware | Siemens | Pxg3.w100-1 | - | All | All | All |
| Operating System | Siemens | Pxg3.w100-1 Firmware | All | All | All | All |
| Hardware | Siemens | Pxg3.w100-2 | - | All | All | All |
| Operating System | Siemens | Pxg3.w100-2 Firmware | All | All | All | All |
| Hardware | Siemens | Pxg3.w200-1 | - | All | All | All |
| Operating System | Siemens | Pxg3.w200-1 Firmware | All | All | All | All |
| Hardware | Siemens | Pxg3.w200-2 | - | All | All | All |
| Operating System | Siemens | Pxg3.w200-2 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| cert-portal.siemens.com/productcert/pdf/ssa-360783.pdf | MISC | cert-portal.siemens.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 591423 Siemens Desigo Control Point Devices (PXM and PXG3) Webserver Multiple Security Vulnerabilities (SSA-360783)