Cross-Site Scripting Vulnerability in Siemens CP 1604 and CP 1616 Devices
CVE-2018-13809
6.1MEDIUM
Summary
A Cross-Site Scripting (XSS) vulnerability has been identified in all versions of Siemens CP 1604 and CP 1616 devices, potentially allowing attackers to execute malicious scripts in the context of a user's session. This vulnerability requires user interaction, as unsuspecting users must be deceived into clicking on a harmful link. While there have been no known incidents of public exploitation at the time of this advisory, organizations using these devices should remain vigilant and apply necessary security measures to mitigate this risk.
Affected Version(s)
CP 1604 All versions
CP 1616 All versions
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved