The vendor explicitly identifies these products as affected by this CVE.
- Climatix POL909 (AWB module)
- Climatix POL909 (AWM module)
- Summary
- The Group Management page of affected devices is vulnerable to cross-site scripting (XSS). The vulnerability allows an attacker to send malicious JavaScript code which could result in hijacking of the user's cookie/session tokens, redirecting the user to a malicious webpage and performing unintended browser action.
- Remediation
- Update to V11.44 or later version
