CVE-2022-24039 Information
Description
A vulnerability has been identified in Desigo PXC4 (All versions < V02.20.142.10-10884) Desigo PXC5 (All versions < V02.20.142.10-10884). The “addCell” JavaScript function fails to properly sanitize user-controllable input before including it into the generated XML body of the XLS report document such that it is possible to inject arbitrary content (e.g. XML tags) into the generated file. An attacker with restricted privileges by poisoning any of the content used to generate XLS reports could be able to leverage the application to deliver malicious files against higher-privileged users and obtain Remote Code Execution (RCE) against the administrator’s workstation.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Reference
https://cert-portal.siemens.com/productcert/pdf/ssa-626968.pdf
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.0
Share on: