CVE-2022-24039
CRITICALDesigo PXC4-5 < V02.20.142.10-10884 - Code Injection
Title source: llmDescription
A vulnerability has been identified in Desigo PXC4 (All versions < V02.20.142.10-10884), Desigo PXC5 (All versions < V02.20.142.10-10884). The “addCell” JavaScript function fails to properly sanitize user-controllable input before including it into the generated XML body of the XLS report document, such that it is possible to inject arbitrary content (e.g., XML tags) into the generated file. An attacker with restricted privileges, by poisoning any of the content used to generate XLS reports, could be able to leverage the application to deliver malicious files against higher-privileged users and obtain Remote Code Execution (RCE) against the administrator’s workstation.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://cert-portal.siemens.com/productcert/pdf/ssa-626968.pdf
Scores
CVSS v3
9.0
EPSS
0.0205
EPSS Percentile
84.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Details
CWE
CWE-75
Status
published
Products (2)
siemens/desigo_pxc4_firmware
< 02.20.142.10-10884
siemens/desigo_pxc5_firmware
< 02.20.142.10-10884
Published
May 10, 2022
Tracked Since
Feb 18, 2026