CVE-2022-4286: Reflected Cross-Site Scripting Vulnerabilities in Automation Runtime
A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to execute arbitrary JavaScript in the context of the users browser session.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-4286?
CVE-2022-4286 is a reflected cross-site scripting (XSS) vulnerability in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93.
What is the impact of CVE-2022-4286?
CVE-2022-4286 allows a remote attacker to execute arbitrary JavaScript in the user's browser session.
How can the XSS vulnerability in CVE-2022-4286 be exploited?
The XSS vulnerability in CVE-2022-4286 can be exploited by tricking a user into clicking on a specially crafted link that contains malicious JavaScript code.
How severe is CVE-2022-4286?
CVE-2022-4286 has a severity value of 6.1, which is considered medium.
How can I fix CVE-2022-4286?
To fix CVE-2022-4286, it is recommended to update B&R Automation Runtime to a version higher than C4.93 or apply any patches provided by the vendor.