CVE-2022-43376
18.04.2023, 20:15
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause code and session manipulation when malicious code is inserted into the browser. Affected Products: NetBotz 4 - 355/450/455/550/570(V4.7.0 and prior)
Vendor | Product | Version |
---|---|---|
schneider-electric | netbotz_355_firmware | 4.0.0 ≤ 𝑥 ≤ 4.7.0 |
schneider-electric | netbotz_450_firmware | 4.0.0 ≤ 𝑥 ≤ 4.7.0 |
schneider-electric | netbotz_455_firmware | 4.0.0 ≤ 𝑥 ≤ 4.7.0 |
schneider-electric | netbotz_550_firmware | 4.0.0 ≤ 𝑥 ≤ 4.7.0 |
schneider-electric | netbotz_570_firmware | 4.0.0 ≤ 𝑥 ≤ 4.7.0 |
𝑥
= Vulnerable software versions
References