CSRF Vulnerability in CP Devices from Siemens
CVE-2018-13810
6.5MEDIUM
Summary
A vulnerability exists in the integrated configuration web server of Siemens CP 1604 and CP 1616 devices, allowing for a Cross-Site Request Forgery (CSRF) attack. This security flaw can be exploited if a legitimate user is deceived into clicking on a malicious link that triggers unauthorized actions through the web interface. Successful exploitation hinges on user interaction, as it requires the legitimate user's participation. As of the advisory publication, there have been no public reports of this vulnerability being exploited.
Affected Version(s)
CP 1604 All versions
CP 1616 All versions
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved