CVE-2022-35416: XSS
Published Jul 11, 2022
·Updated
H3C SSL VPN through 2022-07-10 allows wnm/login/login.json svpnlang cookie XSS.
Affected Software
1 affected component
H3C SSL VPN<=2022-07-10
Event History
Jul 11, 2022
CVE Published
via MITRE·02:58 AM
Data Sourced
via MITRE·02:58 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2022-35416?
CVE-2022-35416 is classified as a high severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2022-35416?
To fix CVE-2022-35416, update your H3C SSL VPN to a version released after 2022-07-10 that addresses the XSS vulnerability.
3
What products are affected by CVE-2022-35416?
CVE-2022-35416 affects H3C SSL VPN software versions up to and including 2022-07-10.
4
What kind of attack is possible with CVE-2022-35416?
CVE-2022-35416 allows an attacker to perform cross-site scripting (XSS) attacks via the svpnlang cookie.
5
Is there a workaround for CVE-2022-35416?
Currently, there is no known workaround for CVE-2022-35416 other than applying the latest software updates.