QID 590742
Date Published: 2022-07-18
QID 590742: Schneider Electric Conext Combox Multiple Vulnerabilities (SEVD-2022-165-03)
AFFECTED PRODUCTS
Conext ComBox All Versions
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
Failure to apply the mitigations provided below may risk Clickjacking, Rate Limiting and Cross-Site Request Forgery attacks. An attacker who successfully exploits one or more of these vulnerabilities could trick the product user admin into performing unintended actions that may lead to taking over their account or manipulating the station settings.
Solution
Customers are advised to refer to CERT MITIGATIONS section SEVD-2022-165-03 for affected packages and patching details.
Vendor References
- SEVD-2022-165-03 -
www.se.com/il/en/download/document/SEVD-2022-165-03/
CVEs related to QID 590742
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SEVD-2022-165-03 |
|