Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-40184

18
FAUCET Score

CVE-2022-40184 describes a stored cross-site scripting (XSS) vulnerability in the web interface of Bosch VIDEOJET multi 4000 devices. An authenticated administrator can inject malicious JavaScript into configuration fields due to incomplete filtering, which then executes for other administrators viewing those settings. This vulnerability has a CVSS score of 4.8 (Medium), indicating a network-based attack with high privileges required, user interaction, and potential for low confidentiality and integrity impact. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
<= 6.31.0010CPE matchmatch criteria
cpe:2.3:o:bosch:videojet_multi_4000_firmware:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.1MEDIUM

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
1.0
Impact Score
3.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
22.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 25th percentile among its peer group of 4,937 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (4)

chainsafevendor investigatingvia llm_extracted
gogsvendor investigatingvia llm_extracted
openpgpjsvendor investigatingvia llm_extracted
opensslvendor investigatingvia llm_extracted

Vendor Advisories (4)

openpgpjsllm-openpgpjs-d71122de22c5323eMEDIUM

Multiple Cross Site Scripting vulnerabilities in Bosch VIDEOJET multi 4000

Oct 19, 2022
opensslllm-openssl-1f054dfb55c6fabcMEDIUM

Multiple Cross Site Scripting vulnerabilities in Bosch VIDEOJET multi 4000

Oct 19, 2022
gogsllm-gogs-a4aa580057bd1a5cMEDIUM

Multiple Cross Site Scripting vulnerabilities in Bosch VIDEOJET multi 4000

Oct 19, 2022
chainsafellm-chainsafe-a1353da41ac1711fMEDIUM

Multiple Cross Site Scripting vulnerabilities in Bosch VIDEOJET multi 4000

Oct 19, 2022

References

psirt.bosch.com / security-advisories/bosch-sa-454166-bt.html
PatchVendor Advisory