CVE-2022-43376
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause code and session manipulation when malicious code is inserted into the browser. Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0 and prior)
Published:Apr 18, 2023
Last Modified:Feb 5, 2025
EPS:Apr 18, 2023
EPSS Score:0.00305
CVSS Score:7.6
Affected Products
Vendor
Product
Action
Vendor
Schneider-electric
Product
Netbotz 355
Schneider-electric
Netbotz 355
Vendor
Schneider-electric
Product
Netbotz 355 Firmware
Schneider-electric
Netbotz 355 Firmware
Vendor
Schneider-electric
Product
Netbotz 450
Schneider-electric
Netbotz 450
Vendor
Schneider-electric
Product
Netbotz 450 Firmware
Schneider-electric
Netbotz 450 Firmware
Vendor
Schneider-electric
Product
Netbotz 455
Schneider-electric
Netbotz 455
Vendor
Schneider-electric
Product
Netbotz 455 Firmware
Schneider-electric
Netbotz 455 Firmware
Vendor
Schneider-electric
Product
Netbotz 550
Schneider-electric
Netbotz 550
Vendor
Schneider-electric
Product
Netbotz 550 Firmware
Schneider-electric
Netbotz 550 Firmware
Vendor
Schneider-electric
Product
Netbotz 570
Schneider-electric
Netbotz 570
Vendor
Schneider-electric
Product
Netbotz 570 Firmware
Schneider-electric
Netbotz 570 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
