Vulnerability record · CVE-2022-45938 · published 2 June 2023
CVE-2022-45938: Comcast microeisbss stored XSS in Device ID field leads to RCE
Xfinity · Comcast Defined Technologies Microeisbss
Comcast Defined Technologies microeisbss through 2021 contains a stored cross-site scripting flaw in the Device ID field under Inventory Management. Because the injected payload is stored and later rendered, it can be used to execute script in the context of other users and, per the description, escalate to remote code execution and privilege escalation.
Description
An issue was discovered in Comcast Defined Technologies microeisbss through 2021. An attacker can inject a stored XSS payload in the Device ID field under Inventory Management to achieve Remote Code Execution and privilege escalation..
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Automated analysis
high priorityCritical CVSS score and high EPSS with a public exploit write-up, but exploitation requires authentication and user interaction and no KEV listing is present.
What it is
Comcast Defined Technologies microeisbss through 2021 contains a stored cross-site scripting flaw in the Device ID field under Inventory Management. Because the injected payload is stored and later rendered, it can be used to execute script in the context of other users and, per the description, escalate to remote code execution and privilege escalation.
Impact
An attacker can run script in a victim's browser session, potentially leading to remote code execution and privilege escalation within the application. The CVSS scope change and high confidentiality, integrity and availability scores indicate broad impact beyond the vulnerable component.
Attack surface
The flaw is network-reachable (AV:N) and requires low privileges (PR:L) plus user interaction (UI:R), meaning an authenticated low-privileged user must enter the payload into the Device ID field and another user must view the affected inventory page.
Exploitation
No CISA KEV listing and no ransomware association are recorded. EPSS is high (0.45078, 98.7th percentile) and a public exploit write-up is referenced, but the record does not confirm active exploitation.
What to do
- Apply the vendor fix for microeisbss; contact Comcast Defined Technologies support if no patch is published.
- Encode or sanitize all output of the Device ID field and validate input server-side before storage.
- Restrict access to Inventory Management to the minimum set of users who need it.
- Deploy a content security policy that blocks inline script execution to reduce XSS impact.
- Monitor for unexpected script content in inventory records and alert on it.
Detection
- Search inventory database records and application logs for script tags or event handlers in the Device ID field.
- Monitor web requests that submit Device ID values containing HTML or JavaScript syntax.
- Review browser or proxy logs for script execution originating from the inventory management pages.
- Alert on new administrative or privileged accounts created shortly after inventory edits.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://my.xfinity.com/vulnerabilityreport | Not Applicable |
| https://pensecure.medium.com/cve-2022-45938-f4c0d441da6f | ExploitPress/Media Coverage |
| https://my.xfinity.com/vulnerabilityreport | Not Applicable |
| https://pensecure.medium.com/cve-2022-45938-f4c0d441da6f | ExploitPress/Media Coverage |
Track CVE-2022-45938 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-45938), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.