CVE-2024-36140

MEDIUM

OZW672 and OZW772 Firmware < 5.2 - Authenticated Stored Cross-Site Scripting in User Accounts Tab

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2). The user accounts tab of affected devices is vulnerable to stored cross-site scripting (XSS) attacks. This could allow an authenticated remote attacker to inject arbitrary JavaScript code that is later executed by another authenticated victim user with potential higher privileges than the attacker.

References (1)

Core 1

Scores

CVSS v3 6.8
EPSS 0.0020
EPSS Percentile 42.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
siemens/ozw672_firmware < 5.2
siemens/ozw772_firmware < 5.2
Published Nov 12, 2024
Tracked Since Feb 18, 2026