CSRF Vulnerability in CP Devices from Siemens
CVE-2018-13810
6.5MEDIUM
What is CVE-2018-13810?
A vulnerability exists in the integrated configuration web server of Siemens CP 1604 and CP 1616 devices, allowing for a Cross-Site Request Forgery (CSRF) attack. This security flaw can be exploited if a legitimate user is deceived into clicking on a malicious link that triggers unauthorized actions through the web interface. Successful exploitation hinges on user interaction, as it requires the legitimate user's participation. As of the advisory publication, there have been no public reports of this vulnerability being exploited.
Affected Version(s)
CP 1604 All versions
CP 1616 All versions