S4E just found a high-severity finding from cve-2026-42945 scanner (version based)
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-35416 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in H3C SSL VPN affects v. through 2022-07-10.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.9k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-35416
6.1
CVSS

H3C SSL VPN through 2022-07-10 allows wnm/login/login.json svpnlang cookie XSS.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

H3C SSL VPN is a network security product used by businesses around the world to establish secure remote access to their internal networks. Installed on client machines, this software enables remote workers to access the corporate network from virtually anywhere in the world. It is a crucial tool for professionals, allowing them to remain productive while on the go.

Recently, a critical vulnerability was detected in the H3C SSL VPN. CVE-2022-35416 allows attackers to execute XSS (cross-site scripting) attacks by manipulating the svpnlang cookie in the wnm/login/login.json file. This vulnerability can be exploited by malicious actors to gain access to sensitive company data and cause significant damage to an organization’s reputation.

When the svpnlang cookie is exploited, an attacker can inject malicious scripts into a user's browser and steal their session cookies. As a result, the attacker can gain access to the corporate network and sensitive information, such as passwords and financial data. They can also use the compromised system as a staging ground for launching further attacks.

In conclusion, s4e.io is an exceptional platform that provides a range of security features. If you want to stay informed about vulnerability management and cybersecurity developments, the platform offers a comprehensive solution. By leveraging the pro feature of s4e.io, companies can gain insight into potential security threats before they inflict any harm. As a result, clients can take the necessary actions to secure their digital assets and drive their business forward.

 

REFERENCES

Solution Advice

To protect against the CVE-2022-35416 vulnerability, it is essential to take the necessary precautions. Below is a bullet list of actions that can be taken to protect against this vulnerability:

  • Update H3C SSL VPN software to the latest version as soon as possible.
  • Restrict access to the VPN to only verified IP addresses.
  • Enable SSL VPN audit and logging to monitor network activity.
  • Deploy robust firewalls to identify and block malicious traffic.
  • Train employees on how to recognize and report potential security threats.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.