CVE-2021-22291: EIBPORT Reflected XSS
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT V3 KNX, ABB EIBPORT V3 KNX GSM.This issue affects EIBPORT V3 KNX: before 3.9.2; EIBPORT V3 KNX GSM: before 3.9.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22291?
CVE-2021-22291 is classified as a medium severity vulnerability due to improper neutralization of input during web page generation, leading to potential cross-site scripting (XSS) attacks.
How do I fix CVE-2021-22291?
To mitigate CVE-2021-22291, upgrade to ABB EIBPORT V3 KNX version 3.9.2 or later.
Which products are affected by CVE-2021-22291?
CVE-2021-22291 affects ABB EIBPORT V3 KNX and ABB EIBPORT V3 KNX GSM, both versions prior to 3.9.2.
What kind of attacks can CVE-2021-22291 allow?
CVE-2021-22291 can allow attackers to execute malicious scripts in the context of a user's browser session, facilitating cross-site scripting (XSS) attacks.
When was CVE-2021-22291 discovered?
CVE-2021-22291 was publicly disclosed in 2021, emphasizing the need for immediate attention to affected versions.