Back to Database
Status published
High
CVE-2022-2140
Elcomplus SmartICS Cross-site Scripting
Vulnerability Description
Elcomplus SmartICS v2.3.4.0 does not neutralize user-controllable input, which allows an authenticated user to inject arbitrary code into specific parameters.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-2140
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Michael Heinzl reported these vulnerabilities to CISA.
More from Elcomplus
View All →CVE-2022-2106
Elcomplus SmartICS Path Traversal
Low
3.8
CVE-2022-2088
Elcomplus SmartICS Access Control
Medium
6.8
CVE-2021-43939
Elcomplus SmartPtt Improper Authorization
High
8.8
CVE-2021-43938
Elcomplus SmartPTT SCADA Server Information Exposure
High
8.1
CVE-2021-43937
Elcomplus SmartPTT SCADA Server Cross-site Request Forgery
High
7.6
Affected Vendor
Elcomplus
View all reports →Affected Software
SmartICS
Vulnerable Versions:
v2.3.4.0
Timeline
Official Publish:
June 27th, 2022
Last Modified:
April 16th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H