← Vulnerability feed

Vulnerability record · CVE-2022-45938 · published 2 June 2023

CVE-2022-45938: Comcast microeisbss stored XSS in Device ID field leads to RCE

Xfinity · Comcast Defined Technologies Microeisbss

Comcast Defined Technologies microeisbss through 2021 contains a stored cross-site scripting flaw in the Device ID field under Inventory Management. Because the injected payload is stored and later rendered, it can be used to execute script in the context of other users and, per the description, escalate to remote code execution and privilege escalation.

9.0 CVSS 3.1 Critical EPSS 45% · top 1.3% CWE-79 · Cross-site scripting
9.0CVSS 3.1 base score
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device ID field under Inventory Management to achieve Remote Code Execution and privilege escalation..

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCritical CVSS score and high EPSS with a public exploit write-up, but exploitation requires authentication and user interaction and no KEV listing is present.

What it is

Comcast Defined Technologies microeisbss through 2021 contains a stored cross-site scripting flaw in the Device ID field under Inventory Management. Because the injected payload is stored and later rendered, it can be used to execute script in the context of other users and, per the description, escalate to remote code execution and privilege escalation.

Impact

An attacker can run script in a victim's browser session, potentially leading to remote code execution and privilege escalation within the application. The CVSS scope change and high confidentiality, integrity and availability scores indicate broad impact beyond the vulnerable component.

Attack surface

The flaw is network-reachable (AV:N) and requires low privileges (PR:L) plus user interaction (UI:R), meaning an authenticated low-privileged user must enter the payload into the Device ID field and another user must view the affected inventory page.

Exploitation

No CISA KEV listing and no ransomware association are recorded. EPSS is high (0.45078, 98.7th percentile) and a public exploit write-up is referenced, but the record does not confirm active exploitation.

What to do

  • Apply the vendor fix for microeisbss; contact Comcast Defined Technologies support if no patch is published.
  • Encode or sanitize all output of the Device ID field and validate input server-side before storage.
  • Restrict access to Inventory Management to the minimum set of users who need it.
  • Deploy a content security policy that blocks inline script execution to reduce XSS impact.
  • Monitor for unexpected script content in inventory records and alert on it.

Detection

  • Search inventory database records and application logs for script tags or event handlers in the Device ID field.
  • Monitor web requests that submit Device ID values containing HTML or JavaScript syntax.
  • Review browser or proxy logs for script execution originating from the inventory management pages.
  • Alert on new administrative or privileged accounts created shortly after inventory edits.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-45938 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2026-42897Microsoft Exchange Server XSS enables spoofingMicrosoft Exchange Server and Exchange Server Subscription Edition fail to neutralize input during web page generation, a cross-site scripting flaw (…KEVEPSS 0.52%analysed6.1CVE-2025-48700Zimbra Classic UI stored XSS via crafted email HTMLZimbra Collaboration Suite Classic UI fails to properly sanitize HTML content in email messages, allowing crafted tag structures and attribute values…KEVEPSS 1.7%analysed6.1CVE-2025-66376Zimbra Collaboration Classic UI stored XSS via CSS @import in emailZimbra Collaboration Suite 10 before 10.0.18 and 10.1 before 10.1.13 allows stored cross-site scripting in the Classic UI through CSS @import directi…KEVEPSS 20%analysed6.1CVE-2025-68461Roundcube Webmail XSS via SVG animate tagRoundcube Webmail before 1.5.12 and 1.6 before 1.6.12 is vulnerable to cross-site scripting through the animate tag in an SVG document. Because the f…KEVEPSS 27%analysed10.0CVE-2026-22769Dell RecoverPoint for Virtual Machines hardcoded credential flawDell RecoverPoint for Virtual Machines versions prior to 6.0.3.1 HF1 contain a hardcoded credential vulnerability (CWE-798). An unauthenticated remot…KEVEPSS 13%analysed7.1CVE-2025-14611Gladinet CentreStack and Triofox hardcoded AES key enables file inclusionCentreStack and Triofox before 16.12.10420.56791 use hardcoded values in their AES cryptoscheme, weakening protection for publicly exposed endpoints.…KEVEPSS 53%analysed5.4CVE-2021-26829OpenPLC ScadaBR stored XSS via system_settings.shtmOpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored cross-site scripting through system_settings.shtm. Because the inj…KEVEPSS 48%analysed5.4CVE-2025-27915Zimbra Classic Web Client stored XSS via ICS file HTMLZimbra Collaboration Suite 9.0, 10.0 and 10.1 fail to sanitize HTML content in ICS files in the Classic Web Client. A malicious ICS entry embedded in…KEVEPSS 4.0%analysed

Source: NIST National Vulnerability Database (record CVE-2022-45938), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.