CVE-2022-43376: XSS
Published Apr 18, 2023
·Updated
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause code and session manipulation when malicious code is inserted into the browser.
Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0
and prior)
Affected Software
10 affected components
Schneider-electric Netbotz 355 Firmware>=4.0.0<=4.7.0
Schneider-electric Netbotz 355
Schneider-electric Netbotz 450 Firmware>=4.0.0<=4.7.0
Schneider-electric Netbotz 450
Schneider-electric Netbotz 455 Firmware>=4.0.0<=4.7.0
Schneider-electric Netbotz 455
Schneider-electric Netbotz 550 Firmware>=4.0.0<=4.7.0
Schneider-electric Netbotz 550
Schneider-electric Netbotz 570 Firmware>=4.0.0<=4.7.0
Schneider-electric Netbotz 570
Remediation
Event History
Apr 18, 2023
CVE Published
via MITRE·07:55 PM
Data Sourced
via MITRE·07:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-43376?
CVE-2022-43376 is a vulnerability that allows code and session manipulation through malicious code inserted into a web page.
2
Which products are affected by CVE-2022-43376?
NetBotz 4 - 355/450/455/550/570 (V4.7.0 and prior) firmware versions are affected by CVE-2022-43376.
3
What is the severity of CVE-2022-43376?
CVE-2022-43376 has a severity rating of 6.1 (High).
4
How can CVE-2022-43376 be exploited?
CVE-2022-43376 can be exploited by inserting malicious code into a browser.
5
Is there a fix for CVE-2022-43376?
Upgrading NetBotz 4 - 355/450/455/550/570 firmware to version 4.7.0 or later will fix CVE-2022-43376.