Cross-Site Request Forgery Vulnerability in Siemens SCALANCE M875
CVE-2018-11447
What is CVE-2018-11447?
A security flaw exists in the web interface of the Siemens SCALANCE M875, which could enable a Cross-Site Request Forgery (CSRF) attack. This vulnerability allows unauthorized actions to be performed on behalf of authenticated administrative users if they inadvertently access a malicious link. If exploited, an attacker could manipulate the web interface, altering device configurations or leveraging other vulnerabilities that require administrative access. At the time of notification, no widespread exploitation had been detected.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SCALANCE M875 SCALANCE M875 All versions
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved