nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-22291 CVE-2021-22291
HIGH
EIBPORT Reflected XSS
Record summary
CVE-2021-22291 has a selected CVSS score of 8.5 (high).
Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ABB EIBPORT V3 KNX, ABB EIBPORT V3 KNX GSM.This issue affects EIBPORT V3 KNX: before 3.9.2; EIBPORT V3 KNX GSM: before 3.9.2.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 7, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
EIBPORT V3 KNXBrowse ABB / EIBPORT V3 KNXDefault status: unaffected | CVE List | Before 3.9.2 | affected |
EIBPORT V3 KNX GSMBrowse ABB / EIBPORT V3 KNX GSMDefault status: unaffected | CVE List | Before 3.9.2 | affected |
References
2search.abb.com
https://search.abb.com/library/Download.aspx?DocumentID=9AKK108471A7808&LanguageCode=en&DocumentPartId=pdf&Action=Launch