VDB
GCVE-110-NCSC-2026-112
GCVE-110-NCSC-2026-112
Advisory PublishedCVSS 6.5/10
Affected devices improperly sanitize user input in their web interface, enabling an authenticated remote attacker with administrative privileges to execute a DOM-based cross-site scripting (XSS) attack.
Weaknesses (CWE)
CWE-306Missing Authentication for Critical FunctionCWE-829Inclusion of Functionality from Untrusted Control SphereCWE-346Origin Validation ErrorCWE-863Incorrect AuthorizationCWE-290Authentication Bypass by SpoofingCWE-307Improper Restriction of Excessive Authentication AttemptsCWE-125Out-of-bounds ReadCWE-835Loop with Unreachable Exit Condition ('Infinite Loop')CWE-862Missing AuthorizationCWE-770Allocation of Resources Without Limits or ThrottlingCWE-80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)CWE-197Numeric Truncation ErrorCWE-295Improper Certificate ValidationCWE-347Improper Verification of Cryptographic SignatureCWE-639Authorization Bypass Through User-Controlled KeyCWE-266Incorrect Privilege AssignmentCWE-305Authentication Bypass by Primary Weakness
Risk Scores
CVSS 3.1
6.5/10
Medium · CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Siemens | vers:unknown/* | — | — |
Aliases
CVE-2020-24588CVE-2020-26139CVE-2020-26140CVE-2020-26141CVE-2020-26143CVE-2020-26144CVE-2020-26146CVE-2020-26147CVE-2021-3712CVE-2022-0778CVE-2022-31765CVE-2022-36323CVE-2022-36324CVE-2022-36325CVE-2023-44373CVE-2025-2884CVE-2025-40745CVE-2025-6965CVE-2026-24032CVE-2026-25654CVE-2026-27668CVE-2026-33892
Browse GCVE Records
73,873 records in the GCVE database · Updated July 20, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.