First published: Tue Feb 14 2023(Updated: )
A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to execute arbitrary JavaScript in the context of the users browser session.
Credit: cybersecurity@ch.abb.com
Affected Software | Affected Version | How to fix |
---|---|---|
B&R Automation Runtime | >=3.00<=c4.93 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4286 is a reflected cross-site scripting (XSS) vulnerability in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93.
CVE-2022-4286 allows a remote attacker to execute arbitrary JavaScript in the user's browser session.
The XSS vulnerability in CVE-2022-4286 can be exploited by tricking a user into clicking on a specially crafted link that contains malicious JavaScript code.
CVE-2022-4286 has a severity value of 6.1, which is considered medium.
To fix CVE-2022-4286, it is recommended to update B&R Automation Runtime to a version higher than C4.93 or apply any patches provided by the vendor.