Cross-Site Request Forgery Vulnerability in Siemens SCALANCE M875
CVE-2018-11447
8.8HIGH
Summary
A security flaw exists in the web interface of the Siemens SCALANCE M875, which could enable a Cross-Site Request Forgery (CSRF) attack. This vulnerability allows unauthorized actions to be performed on behalf of authenticated administrative users if they inadvertently access a malicious link. If exploited, an attacker could manipulate the web interface, altering device configurations or leveraging other vulnerabilities that require administrative access. At the time of notification, no widespread exploitation had been detected.
Affected Version(s)
SCALANCE M875 SCALANCE M875 All versions
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved