6.1

CVE-2022-27237

There is a cross-site scripting (XSS) vulnerability in an NI Web Server component installed with several NI products. Depending on the product(s) in use, remediation guidance includes: install SystemLink version 2021 R3 or later, install FlexLogger 2022 Q2 or later, install LabVIEW 2021 SP1, install G Web Development 2022 R1 or later, or install Static Test Software Suite version 1.2 or later.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NiFlexlogger Version2021 Updater2
NiFlexlogger Version2021 Updater3
NiFlexlogger Version2021 Updater4
NiG Web Development Software Version2021 SwEdition-
NiG Web Development Software Version2021 SwEditioncommunity
NiLabview Version2021 Update- SwEdition-
NiLabview Version2021 Update- SwEditioncommunity
NiStatic Test Software Suite Version < 1.2
NiSystemlink Version2020 Updater4
NiSystemlink Version2022 Updater1
NiSystemlink Version2022 Updater2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.5% 0.644
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.