Cross-Site Request Forgery Vulnerability in Siemens SCALANCE M875
CVE-2018-11447

8.8HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
26 June 2018

Summary

A security flaw exists in the web interface of the Siemens SCALANCE M875, which could enable a Cross-Site Request Forgery (CSRF) attack. This vulnerability allows unauthorized actions to be performed on behalf of authenticated administrative users if they inadvertently access a malicious link. If exploited, an attacker could manipulate the web interface, altering device configurations or leveraging other vulnerabilities that require administrative access. At the time of notification, no widespread exploitation had been detected.

Affected Version(s)

SCALANCE M875 SCALANCE M875 All versions

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.