{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-10-01T14:36:26.635","vulnerabilities":[{"cve":{"id":"CVE-2022-40183","sourceIdentifier":"psirt@bosch.com","published":"2022-10-27T17:15:10.430","lastModified":"2026-06-17T05:01:03.923","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"An error in the URL handler of the VIDEOJET multi 4000 may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the encoder address can send a crafted link to a user, which will execute JavaScript code in the context of the user."},{"lang":"es","value":"Un error en el controlador de URL de VIDEOJET multi 4000 puede provocar un Cross Site Scripting (XSS) reflejado en la interfaz basado en web. Un atacante con conocimiento de la dirección del codificador puede enviar un enlace manipulando a un usuario, que ejecutará código JavaScript en el contexto del usuario."}],"affected":[{"source":"psirt@bosch.com","affectedData":[{"vendor":"Bosch","product":"VIDEOJET multi 4000","versions":[{"version":"unspecified","lessThanOrEqual":"6.31.0010","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"psirt@bosch.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L","baseScore":5.8,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":1.6,"impactScore":3.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":4.7,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":1.6,"impactScore":2.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-05-05T19:04:28.375137Z","id":"CVE-2022-40183","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"psirt@bosch.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:bosch:videojet_multi_4000_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"6.31.0010","matchCriteriaId":"821A0ADF-1601-4688-B3E6-636748D48EE8"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:bosch:videojet_multi_4000:-:*:*:*:*:*:*:*","matchCriteriaId":"19868F38-8A56-451C-AE74-FEADA0FDD6EA"}]}]}],"references":[{"url":"https://psirt.bosch.com/security-advisories/bosch-sa-454166-bt.html","source":"psirt@bosch.com","tags":["Patch","Vendor Advisory"]},{"url":"https://psirt.bosch.com/security-advisories/bosch-sa-454166-bt.html","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}]}}]}