Vulnerability Details CVE-2022-43376
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site
Scripting') vulnerability exists that could cause code and session manipulation when malicious
code is inserted into the browser.
Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0
and prior)
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.2%
CVSS Severity
CVSS v3 Score 7.6
Products affected by CVE-2022-43376
-
cpe:2.3:h:schneider-electric:netbotz_355:-
-
cpe:2.3:h:schneider-electric:netbotz_450:-
-
cpe:2.3:h:schneider-electric:netbotz_455:-
-
cpe:2.3:h:schneider-electric:netbotz_550:-
-
cpe:2.3:h:schneider-electric:netbotz_570:-
-
cpe:2.3:o:schneider-electric:netbotz_355_firmware:*
-
cpe:2.3:o:schneider-electric:netbotz_450_firmware:*
-
cpe:2.3:o:schneider-electric:netbotz_455_firmware:*
-
cpe:2.3:o:schneider-electric:netbotz_550_firmware:*
-
cpe:2.3:o:schneider-electric:netbotz_570_firmware:*