Cross-Site Request Forgery Vulnerability in XHQ by Siemens
CVE-2019-13930

8.1HIGH

Key Information:

Vendor
Siemens Ag
Status
Vendor
CVE Published:
12 December 2019

Summary

A security vulnerability in Siemens' XHQ allows for a potential Cross-Site Request Forgery attack. It exploits the web interface when a user unknowingly accesses a malicious link. For successful exploitation, the attacker requires the legitimate user's interaction, as the user must be authenticated. If successful, the attacker can initiate actions permitted to that user, leading to unauthorized content modification or access within the application. As of the advisory's publication, there was no evidence of public exploitation of this issue.

Affected Version(s)

XHQ All versions < V6.0.0.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.