CSRF Vulnerability in CP Devices from Siemens
CVE-2018-13810

6.5MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
17 April 2019

Summary

A vulnerability exists in the integrated configuration web server of Siemens CP 1604 and CP 1616 devices, allowing for a Cross-Site Request Forgery (CSRF) attack. This security flaw can be exploited if a legitimate user is deceived into clicking on a malicious link that triggers unauthorized actions through the web interface. Successful exploitation hinges on user interaction, as it requires the legitimate user's participation. As of the advisory publication, there have been no public reports of this vulnerability being exploited.

Affected Version(s)

CP 1604 All versions

CP 1616 All versions

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.