CWE
80 79
Advisory Published
Updated

CVE-2022-36325: XSS

First published: Wed Aug 10 2022(Updated: )

Affected devices do not properly sanitize data introduced by an user when rendering the web interface. This could allow an authenticated remote attacker with administrative privileges to inject code and lead to a DOM-based XSS.

Credit: productcert@siemens.com

Affected SoftwareAffected VersionHow to fix
Siemens SCALANCE M-800
Siemens Scalance M-800 Firmware
Siemens Scalance S615 EEC Firmware
Siemens Scalance S615 Firmware
Siemens Scalance S602 Firmware<2.3.1
Siemens SCALANCE SC-600 family
Siemens Scalance SC622-2C Firmware<2.3.1
Siemens Scalance SC622-2C Firmware
Siemens Scalance SC632-2C Firmware<2.3.1
Siemens Scalance SC632-2C Firmware
Siemens Scalance SC636-2C<2.3.1
Siemens Scalance SC636-2C
Siemens Scalance SC642-2C<2.3.1
Siemens SCALANCE SC642-2C
Siemens Scalance SC646-2C Firmware<2.3.1
Siemens SCALANCE SC646-2C (6GK5646-2GS00-2AC2)
Siemens Scalance W700 Firmware
Siemens Scalance W700
Siemens SCALANCE W700
Siemens SCALANCE W-700 IEEE 802.11n family
Siemens Scalance W700 Series Firmware
Siemens SCALANCE W700 IEEE 802.11ac Firmware
Siemens Scalance XB-200 Firmware
Siemens SCALANCE XB-200
Siemens SCALANCE XB205-3 (ST, PN) Firmware
Siemens SCALANCE XB205-3 (SC, PN)
Siemens SCALANCE XB205-3LD
Siemens SCALANCE XB205-3LD
Siemens Scalance XB208
Siemens Scalance XB208
Siemens Scalance XB213-3
Siemens SCALANCE XB213-3 (ST, PN) Firmware
Siemens SCALANCE XB213-3LD Firmware
Siemens Scalance XB213-3LD Firmware
Siemens Scalance XB216
Siemens Scalance XB216
Siemens Scalance XC-200 Firmware
Siemens SCALANCE XC-200
Siemens SCALANCE XC206-2 Firmware
Siemens SCALANCE XC206-2SFP G (EIP DEF.) Firmware
Siemens Scalance XC206-2G PoE
Siemens SCALANCE XC206-2G PoE (54 V DC)
Siemens SCALANCE XC206-2G PoE (54 V DC) Firmware
Siemens SCALANCE XC206-2G PoE EEC (54V DC) Firmware
Siemens Siplus Net Scalance XC206-2SFP
Siemens Scalance XC206-2SFP EEC Firmware
Siemens SCALANCE XC206-2SFP G
Siemens Siplus Net Scalance XC206-2SFP
Siemens Scalance XC206-2SFP G (E/IP) Firmware
Siemens Scalance XC206-2SFP G (E/IP)
Siemens Siplus Net Scalance XC206-2SFP Firmware
Siemens Scalance XC206-2SFP G EEC Firmware
Siemens Siplus Net Scalance XC208 Firmware
Siemens Siplus Net Scalance XC208
Siemens SCALANCE XC208 EEC Firmware
Siemens SCALANCE XC208G Firmware
Siemens SCALANCE XC208G Firmware
Siemens SCALANCE XC208G PoE
Siemens Scalance XC208G (E/IP) Firmware
Siemens Scalance XC208G (E/IP)
Siemens SCALANCE XC208G (EIP DEF.)
Siemens Scalance XC208G (E/IP)
Siemens SCALANCE XC208G Firmware
Siemens SCALANCE XC208G PoE
Siemens Scalance XC216EEC Firmware
Siemens SCALANCE XC216-3G PoE (54 V DC)
Siemens SCALANCE XC216-4C G Firmware
Siemens Scalance XC216-4C Firmware
Siemens Scalance XC216-4C G (E/IP) Firmware
Siemens Scalance XC216-4C G (E/IP)
Siemens Scalance XC216-4C G (E/IP)
Siemens Scalance XC216-4C G (E/IP)
Siemens Scalance XC216-4C G EEC
Siemens Scalance XC216-4C Firmware
Siemens Scalance XC216EEC
Siemens Scalance XC216EEC Firmware
Siemens Scalance Xc224 Firmware
Siemens SCALANCE XC224-4C G
Siemens Scalance XC224-4C G EEC Firmware
Siemens Scalance XC224-4C G (E/IP)
Siemens Scalance XC224-4C G (E/IP) Firmware
Siemens Scalance XC224-4C G (E/IP)
Siemens Scalance XC224-4C G (E/IP) Firmware
Siemens Scalance XC224-4C G (E/IP) Firmware
Siemens Scalance XF-200BA Firmware
Siemens SCALANCE XF-200BA
Siemens Scalance XF204-2BA DNA
Siemens Scalance XF204-2BA DNA
Siemens SCALANCE XF204-2BA IRT Firmware
Siemens Scalance XF204-2BA IRT
Siemens Scalance XM-400 Firmware
Siemens Scalance XM-400
Siemens Scalance XM408-4C L3 Firmware
Siemens Scalance XM408-4C L3
Siemens Scalance XM408-4C L3
Siemens Scalance XM408-4C L3 Firmware
Siemens Scalance XM408-8C L3
Siemens Scalance XM408-8C L3
Siemens Scalance XM408-8C L3
Siemens Scalance XM408-8C
Siemens SCALANCE XM416-4C L3 Firmware
Siemens Scalance XM416-4C Firmware
Siemens Scalance XM416-4C Firmware
Siemens SCALANCE XM416-4C L3 Firmware
Siemens Scalance XP-200 Firmware
Siemens SCALANCE XP-200
Siemens SCALANCE XP208 (Ethernet/IP)
Siemens Scalance XP208 (EIP)
Siemens Scalance XP208 (EIP) Firmware
Siemens Scalance XP208 (EIP)
Siemens Scalance XP208EEC
Siemens SCALANCE XP208PoE EEC
Siemens SCALANCE XP208PoE EEC
Siemens SCALANCE XP208PoE EEC Firmware
Siemens Scalance XP216 (EIP) Firmware
Siemens Scalance XP216 (EIP) Firmware
Siemens Scalance XP216 (EIP) Firmware
Siemens Scalance XP216 (EIP)
Siemens Scalance XP216EEC
Siemens Scalance XP216EEC Firmware
Siemens Scalance XP216PoE EEC
Siemens Scalance XP216PoE EEC Firmware
Siemens Scalance XR-300PoE
Siemens Scalance XR-300 Series
Siemens Scalance XR-300 Series
Siemens Scalance XR-300EEC Firmware
Siemens Scalance XR-300PoE
Siemens Scalance XR-300 Series
Siemens SCALANCE XR300-WG firmware
Siemens SCALANCE X-300WG
Siemens Scalance XR324-12M
Siemens SCALANCE XR324-12M
Siemens Scalance XR324-12M TS
Siemens SCALANCE XR324-12M
Siemens SCALANCE XR324-4M EEC
Siemens Scalance XR324-4M EEC Firmware
Siemens SCALANCE XR324-4M PoE
Siemens SCALANCE XR324-4M EEC
Siemens Scalance XR324-4M PoE TS
Siemens SCALANCE XR324-4M PoE TS
Siemens Scalance XR324WG Firmware
Siemens Scalance XR324WG Firmware
Siemens Scalance XR326-2C POE WG
Siemens SCALANCE XR326-2C PoE WG
Siemens SCALANCE XR328-4C WG
Siemens SCALANCE XR328-4C WG
Siemens SCALANCE XR-500 Firmware
Siemens SCALANCE XR-500 Firmware
Siemens Scalance XR524
Siemens Scalance XR524-8C
Siemens Scalance XR524-8C
Siemens Scalance XR524
Siemens Scalance XR524-8C L3
Siemens Scalance XR524-8C
Siemens Scalance XR526-8C Firmware
Siemens Scalance XR526-8C Firmware
Siemens Scalance XR526-8C L3 Firmware
Siemens Scalance XR526-8C Firmware
Siemens Scalance XR526-8C Firmware
Siemens Scalance XR526-8C L3 Firmware
Siemens Scalance XR528-6M Firmware
Siemens Scalance XR528-6M Firmware
Siemens Scalance XR528-6M L3
Siemens Scalance XR528-6M 2HR2 Firmware
Siemens Scalance XR528-6M
Siemens Scalance XR528-6M 2HR2 Firmware
Siemens Scalance XR528-6M 2HR2 Firmware
Siemens Scalance XR528-6M 2HR2 Firmware
Siemens Scalance XR528-6M L3
Siemens Scalance XR528-6M
Siemens Scalance XR552-12 Firmware
Siemens Scalance XR552-12
Siemens Scalance XR552 Firmware
Siemens Scalance XR552 Firmware
Siemens Scalance XR552 Firmware
Siemens Scalance XR552 Firmware
Siemens Scalance XR552 Firmware
Siemens Scalance XR552
Siemens Scalance XR552-12M 2HR2 Firmware
Siemens Scalance XR552-12M Firmware

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2022-36325?

    CVE-2022-36325 is classified as a medium to high severity vulnerability due to its potential for code injection and execution.

  • How do I fix CVE-2022-36325?

    To mitigate CVE-2022-36325, ensure that you update the affected Siemens SCALANCE devices to the latest firmware version that addresses this vulnerability.

  • What type of vulnerability is CVE-2022-36325?

    CVE-2022-36325 is a DOM-based cross-site scripting (XSS) vulnerability caused by improper data sanitization in the web interface.

  • Who is affected by CVE-2022-36325?

    Only authenticated remote attackers with administrative privileges can exploit CVE-2022-36325 on affected Siemens SCALANCE devices.

  • What devices are affected by CVE-2022-36325?

    CVE-2022-36325 affects various Siemens SCALANCE devices, particularly those with specific firmware versions that do not properly sanitize user input.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203