CVE Database
/

CVE-2022-42786

Back to search

CVE-2022-42786

Published: Nov 10, 2022

Modified: Apr 29, 2025

PUBLISHED

CVSS v3.1

5.4

MEDIUM

Description

Multiple W&T Products of the ComServer Series are prone to an XSS attack. An authenticated remote Attacker can execute arbitrary web scripts or HTML via a crafted payload injected into the title of the configuration webpage

VendorProductVersions

Wiesemann & Theis

Com-Server LC

affected
1.0 - < 1.48

Wiesemann & Theis

Com-Server PoE 3 x Isolated

affected
1.0 - < 1.48

Wiesemann & Theis

Com-Server 20mA

affected
1.0 - < 1.48

Wiesemann & Theis

Com-Server ++

affected
1.0 - < 1.48

Wiesemann & Theis

AT-Modem-Emulator

affected
1.0 - < 1.48

Wiesemann & Theis

Com-Server UL

affected
1.0 - < 1.48

Wiesemann & Theis

Com-Server Highspeed 100BaseFX

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed 100BaseLX

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed Office 1 Port

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed Office 4 Port

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed Industry

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed OEM

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed Compact

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed Isolated

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed 19" 1Port

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed 19" 4Port

affected
1.0 - < 1.76

Wiesemann & Theis

Com-Server Highspeed PoE

affected
1.0 - < 1.76

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

Required

Scope

Changed

Confidentiality

Low

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now