CVE-2022-45028: XSS
Published Dec 13, 2022
·Updated
A cross-site scripting (XSS) vulnerability in Arris NVG443B 9.3.0h3d36 allows attackers to execute arbitrary web scripts or HTML via a crafted POST request sent to /cgi-bin/logs.ha.
Affected Software
4 affected components
Arris Nvg443b Firmware=9.3.0h3d36
Arris NVG443B
All of the following
Arris Nvg443b Firmware=9.3.0h3d36
Arris NVG443B
Event History
Dec 13, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-45028.
2
What is the severity level of CVE-2022-45028?
The severity level of CVE-2022-45028 is medium.
3
How does the vulnerability CVE-2022-45028 work?
The vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted POST request sent to /cgi-bin/logs.ha.
4
Which software version is affected by CVE-2022-45028?
The Arris NVG443B firmware version 9.3.0h3d36 is affected by CVE-2022-45028.
5
Is there a fix available for CVE-2022-45028?
There may be a fix available for CVE-2022-45028, please refer to the provided references for more information.