← Back to home
SIEMENS-SSA-230445  ·  Published 2024-11-12  ·  View on Siemens ProductCERT ↗

SSA-230445 V1.0: Stored XSS Vulnerability in OZW Web Servers Before V5.2

CVSS N/A MEDIUM

Risk Summary

<p>OZW672 and OZW772 Web Server versions before V5.2 contain a stored cross-site scripting (XSS) vulnerability that could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker.</p> <p>Siemens has released new versions for the affected products and recommends to update to the latest versions.</p>

Remediations

  • Refer to Siemens ProductCERT advisory for patch and remediation guidance.

Affected Vendors

Siemens

Affected Products (1)

Siemens · SSA-230445 V1.0: Stored XSS Vulnerability in OZW Web Servers Before V5.2 See advisory

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more