The vendor explicitly identifies these products as affected by this CVE.
- Desigo PXM30-1
- Desigo PXM30.E
- Desigo PXM40-1
- Desigo PXM40.E
- Desigo PXM50-1
- Desigo PXM50.E
- PXG3.W100-1
- PXG3.W100-2
- PXG3.W200-1
- PXG3.W200-2
- Summary
- Improper Neutralization of Input During Web Page Generation exists in the “Import Files“ functionality of the “Operation” web application, due to the missing validation of the titles of files included in the input package. By uploading a specifically crafted graphics package, a remote low-privileged attacker can execute arbitrary JavaScript code.
- Remediation
- Update to V02.20.126.11-41 or later version. Please contact your local Siemens office for additional support in obtaining the update.
