First published: Mon Jul 11 2022(Updated: )
H3C SSL VPN through 2022-07-10 allows wnm/login/login.json svpnlang cookie XSS.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
H3C SSL VPN | <=2022-07-10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35416 is classified as a high severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
To fix CVE-2022-35416, update your H3C SSL VPN to a version released after 2022-07-10 that addresses the XSS vulnerability.
CVE-2022-35416 affects H3C SSL VPN software versions up to and including 2022-07-10.
CVE-2022-35416 allows an attacker to perform cross-site scripting (XSS) attacks via the svpnlang cookie.
Currently, there is no known workaround for CVE-2022-35416 other than applying the latest software updates.