Cross-Site Scripting Vulnerability in Siemens Spectrum Power Interfaces
CVE-2019-10933
Key Information:
Summary
A vulnerability exists in the web interface of Siemens Spectrum Power products that could allow Cross-Site Scripting (XSS) attacks. This occurs when users are tricked into clicking a malicious link, enabling attackers to execute scripts in the context of the user's session. Importantly, this vulnerability does not require users to be logged into the interface, and at the time of this advisory, there are no known instances of public exploitation. Organizations using these affected versions should take necessary precautions to mitigate potential risks.
Affected Version(s)
Spectrum Power 3 (Corporate User Interface) All versions <= v3.11
Spectrum Power 4 (Corporate User Interface) Version v4.75
Spectrum Power 5 (Corporate User Interface) All versions < v5.50
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved