Cross-Site Scripting Vulnerability in Siemens Spectrum Power Interfaces
CVE-2019-10933

6.1MEDIUM

Summary

A vulnerability exists in the web interface of Siemens Spectrum Power products that could allow Cross-Site Scripting (XSS) attacks. This occurs when users are tricked into clicking a malicious link, enabling attackers to execute scripts in the context of the user's session. Importantly, this vulnerability does not require users to be logged into the interface, and at the time of this advisory, there are no known instances of public exploitation. Organizations using these affected versions should take necessary precautions to mitigate potential risks.

Affected Version(s)

Spectrum Power 3 (Corporate User Interface) All versions <= v3.11

Spectrum Power 4 (Corporate User Interface) Version v4.75

Spectrum Power 5 (Corporate User Interface) All versions < v5.50

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.