Aller au contenu

Fiche vulnérabilité

CVE-2024-36140 : faille moyenne siemens ozw672 firmware (CVSS 5.4)

Description

A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable to stored cross-site scripting (XSS) attacks. This could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker.

En bref

Sévérité
Moyenne (CVSS 5.4)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitation active
Non signalée par la CISA
Publication
12 nov. 2024
Dernière mise à jour
17 juin 2026

Produits concernés

  • siemens ozw672 firmware
  • siemens ozw772 firmware

Références

Rechercher une autre vulnérabilité dans la base CVE