CVE-2023-22585: Reflected Cross-Site Scripting in Danfoss AK-EM100
Published Jun 11, 2023
·Updated
The Danfoss AK-EM100 web applications allow for Reflected Cross-Site Scripting in the title parameter.
Affected Software
4 affected components
Danfoss Ak-em100 Firmware<2.2.0.12
Danfoss AK-EM100
All of the following
Danfoss Ak-em100 Firmware<2.2.0.12
Danfoss AK-EM100
Event History
Jun 11, 2023
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-22585.
2
What is the severity of CVE-2023-22585?
The severity of CVE-2023-22585 is critical with a CVSS score of 6.1.
3
How does CVE-2023-22585 impact the Danfoss AK-EM100 web applications?
CVE-2023-22585 allows for Reflected Cross-Site Scripting in the title parameter of the Danfoss AK-EM100 web applications.
4
Which versions of the Danfoss AK-EM100 Firmware are affected by CVE-2023-22585?
Versions up to 2.2.0.12 of the Danfoss AK-EM100 Firmware are affected by CVE-2023-22585.
5
How can I fix CVE-2023-22585?
To fix CVE-2023-22585, update the Danfoss AK-EM100 Firmware to a version higher than 2.2.0.12.