4.8
CVE-2022-28624
- EPSS 0.46%
- Veröffentlicht 08.07.2022 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:57:36
- Quelle security-alert@hpe.com
- Teams Watchlist Login
- Unerledigt Login
A potential security vulnerability has been identified in certain HPE FlexNetwork and FlexFabric switch products. The vulnerability could be remotely exploited to allow cross site scripting (XSS). HPE has made the following software updates to resolve the vulnerability. HPE FlexNetwork 5130EL_7.10.R3507P02 and HPE FlexFabric 5945_7.10.R6635.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hpe ≫ Flexnetwork 5130 Ei Firmware Version7.10.r3507p02
Hpe ≫ Flexfabric 5945 Firmware Version7.10.r6635
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.46% | 0.629 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.8 | 1.7 | 2.7 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
|
nvd@nist.gov | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:N/I:P/A:N
|
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.