6.5

CVE-2022-43378







A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that
could cause the user to be tricked into performing unintended actions when external address
frames are not properly restricted.





 Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0

 and prior)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electric ≫ Netbotz 355 Firmware Version >= 4.0.0 <= 4.7.0
   Schneider-electric ≫ Netbotz 355 Version -
Schneider-electric ≫ Netbotz 450 Firmware Version >= 4.0.0 <= 4.7.0
   Schneider-electric ≫ Netbotz 450 Version -
Schneider-electric ≫ Netbotz 455 Firmware Version >= 4.0.0 <= 4.7.0
   Schneider-electric ≫ Netbotz 455 Version -
Schneider-electric ≫ Netbotz 550 Firmware Version >= 4.0.0 <= 4.7.0
   Schneider-electric ≫ Netbotz 550 Version -
Schneider-electric ≫ Netbotz 570 Firmware Version >= 4.0.0 <= 4.7.0
   Schneider-electric ≫ Netbotz 570 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.46% 0.365
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
SE.com 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
CWE-1021 Improper Restriction of Rendered UI Layers or Frames

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-312-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-312-01-NetBotz_4_Security_Notification.pdf
Patch
Vendor Advisory