Technical Bulletin
To: DW Customers
Date: August 20, 2026
Re: CVE-2020-11022 & CVE-2020-11023 jQuery XSS Vulnerability
CVE-2020-11022 & CVE-2020-11023 jQuery XSS Vulnerability
-----------------------------------
Affected Models: VMAX IP G4, VMAX A1 G4, VMAX IP Plus, VMAX A1 Plus (discontinued)
-----------------------------------
Known Issue Notice
A potential XSS vulnerability has been brough forward for VMAX recorders that use older versions of jQuery.
This potential security concern has been noted in the past and developers have already implemented defenses against the relevant vulnerabilities. As a result, even though older jQuery components are still present, there are currently no exposed vectors through which an attacker could directly execute malicious scripts.
Developers are actively developing a new web interface that removes jQuery dependency completely and is currently undergoing testing.
System Impact
This jQuery XSS vulnerability has low severity and there are currently no exposed vectors through which the recorder and its assets can be exploited by bad actors.
The vulnerability has been addressed through updates to the recorder firmware and its features.
New firmware versions that address security concerns, based on the existing jQuery interface, will continue to be provided until the new web platform is launched.
______________________________________________________________________________
For More Information or Technical Support
DW Technical Support: https://www.digital-watchdog.com/contact-tech-support/
DW Sales: sales@digital-watchdog.com | www.digital-watchdog.com
Rev: 06/25 Copyright © DW. All rights reserved. Specifications and pricing subject to change without notice.