{"document":{"acknowledgments":[{"organization":"CERT@VDE","summary":"coordination","urls":["https://certvde.com"]}],"category":"csaf_security_advisory","csaf_version":"2.0","distribution":{"tlp":{"label":"WHITE","url":"https://www.first.org/tlp/"}},"lang":"en-GB","notes":[{"category":"summary","text":"A reflected cross-site scripting vulnerability exists in the System Diagnostics Manager (SDM) component of SIMA² Master Stations.","title":"Summary"},{"category":"description","text":"Please consult the CVE details.","title":"Impact"},{"category":"description","text":"Do not use Hyperlinks provided by untrusted 3rd party to access the SIMA² System Diagnostics Manager. Hyperlinks may be provided via:\n\n- Emails from unknown users\n- Social media channels\n- Messaging services\n- Webpages with comment functionality\n- QR Codes\n\nThe use of external Web Application Firewalls (WAF) can mitigate attacks using reflected cross-site scripting.","title":"Mitigation"}],"publisher":{"category":"vendor","contact_details":"psirt@auma.com","name":"AUMA Riester GmbH & Co. KG","namespace":"https://auma.com"},"references":[{"category":"self","summary":"VDE-2023-027: AUMA: Reflected Cross-Site Scripting Vulnerability in SIMA Master Stations - HTML","url":"https://certvde.com/en/advisories/VDE-2023-027/"},{"category":"self","summary":"VDE-2023-027: AUMA: Reflected Cross-Site Scripting Vulnerability in SIMA Master Stations - CSAF","url":"https://auma.csaf-tp.certvde.com/.well-known/csaf/white/2023/vde-2023-027.json"},{"category":"external","summary":"Vendor PSIRT","url":"https://auma.com"},{"category":"external","summary":"CERT@VDE Security Advisories for AUMA Riester GmbH & Co. KG","url":"https://certvde.com/en/advisories/vendor/auma/"}],"title":"AUMA: Reflected Cross-Site Scripting Vulnerability in SIMA Master Stations","tracking":{"aliases":["VDE-2023-027"],"current_release_date":"2023-08-07T09:35:00.000Z","generator":{"date":"2025-06-23T09:05:21.023Z","engine":{"name":"Secvisogram","version":"2.5.28"}},"id":"VDE-2023-027","initial_release_date":"2023-08-07T09:35:00.000Z","revision_history":[{"date":"2023-08-07T09:35:00.000Z","number":"1.0.0","summary":"Initial revision."}],"status":"final","version":"1.0.0"}},"product_tree":{"branches":[{"branches":[{"branches":[{"branches":[{"category":"product_version_range","name":"vers:all/*","product":{"name":"SIMA² Master Station vers:all/*","product_id":"CSAFPID-51001"}}],"category":"product_name","name":"SIMA² Master Station"}],"category":"product_family","name":"Software"}],"category":"vendor","name":"AUMA"}]},"vulnerabilities":[{"cve":"CVE-2022-4286","cwe":{"id":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')"},"notes":[{"category":"description","text":"\nA reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to execute arbitrary JavaScript in the context of the users browser session.\n\n","title":"Vulnerability Description"}],"product_status":{"known_affected":["CSAFPID-51001"]},"remediations":[{"category":"mitigation","details":"Do not use Hyperlinks provided by untrusted 3rd party to access the SIMA² System Diagnostics Manager. Hyperlinks may be provided via:\n\n- Emails from unknown users\n- Social media channels\n- Messaging services\n- Webpages with comment functionality\n- QR Codes\n\nThe use of external Web Application Firewalls (WAF) can mitigate attacks using reflected cross-site scripting.","product_ids":["CSAFPID-51001"]}],"scores":[{"cvss_v3":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":6.1,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","environmentalScore":6.1,"environmentalSeverity":"MEDIUM","integrityImpact":"LOW","privilegesRequired":"NONE","scope":"CHANGED","temporalScore":6.1,"temporalSeverity":"MEDIUM","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","version":"3.1"},"products":["CSAFPID-51001"]}],"title":"CVE-2022-4286"}]}