Web Application Vulnerability in XHQ by Siemens
CVE-2019-13932

9.1CRITICAL

Key Information:

Vendor
Siemens Ag
Status
Vendor
CVE Published:
12 December 2019

Summary

A vulnerability has been identified in the XHQ web application developed by Siemens, affecting all versions prior to V6.0.0.2. This security flaw allows for manipulation of web application requests, potentially causing the application to behave unpredictably for legitimate users. Attackers can exploit this vulnerability without requiring authentication, enabling them to import malicious scripts or generate harmful links. Consequently, they could gain unauthorized access to read or modify the content within the application. As of the time of the advisory's publication, there were no known instances of this vulnerability being publicly exploited.

Affected Version(s)

XHQ All versions < V6.0.0.2

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.