SSA-230445 PUBLISHED CVSS 6.800000190734863 MEDIUM

OZW672 and OZW772 Web Server versions before V5.2 contain a stored cross-site scripting (XSS) vulnerability that could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker. Siemens has released new versions for the affected products and recommends to update to the latest versions.

Risk Scores

CVSS v3.1
6.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N

Affected Products

VendorProductVersions
OZW672
OZW772

Timeline

References

Open in Interactive Console →