Cross-Site Scripting Vulnerability in Siemens WinCC HMI Web Server
CVE-2011-4511

Currently unrated

Key Information:

Vendor

Siemens

Vendor
CVE Published:
3 February 2012

What is CVE-2011-4511?

A Cross-Site Scripting (XSS) vulnerability exists in the HMI web server of Siemens WinCC products, allowing attackers to inject arbitrary web scripts or HTML content through unspecified vectors. This issue affects multiple versions, including WinCC flexible series and various SIMATIC HMI panels, posing a risk when these products are accessed remotely.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.