CVE Database
/

CVE-2022-40182

Back to search

CVE-2022-40182

Published: Oct 11, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

A vulnerability has been identified in Desigo PXM30-1 (All versions < V02.20.126.11-41), Desigo PXM30.E (All versions < V02.20.126.11-41), Desigo PXM40-1 (All versions < V02.20.126.11-41), Desigo PXM40.E (All versions < V02.20.126.11-41), Desigo PXM50-1 (All versions < V02.20.126.11-41), Desigo PXM50.E (All versions < V02.20.126.11-41), PXG3.W100-1 (All versions < V02.20.126.11-37), PXG3.W100-2 (All versions < V02.20.126.11-41), PXG3.W200-1 (All versions < V02.20.126.11-37), PXG3.W200-2 (All versions < V02.20.126.11-41). The device embedded Chromium-based browser is launched as root with the “--no-sandbox” option. Attackers can add arbitrary JavaScript code inside “Operation” graphics and successfully exploit any number of publicly known vulnerabilities against the version of the embedded Chromium-based browser.

VendorProductVersions

Siemens

Desigo PXM30-1

affected
All versions < V02.20.126.11-41

Siemens

Desigo PXM30.E

affected
All versions < V02.20.126.11-41

Siemens

Desigo PXM40-1

affected
All versions < V02.20.126.11-41

Siemens

Desigo PXM40.E

affected
All versions < V02.20.126.11-41

Siemens

Desigo PXM50-1

affected
All versions < V02.20.126.11-41

Siemens

Desigo PXM50.E

affected
All versions < V02.20.126.11-41

Siemens

PXG3.W100-1

affected
All versions < V02.20.126.11-37

Siemens

PXG3.W100-2

affected
All versions < V02.20.126.11-41

Siemens

PXG3.W200-1

affected
All versions < V02.20.126.11-37

Siemens

PXG3.W200-2

affected
All versions < V02.20.126.11-41

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now