Cross-Site Scripting Vulnerability in Siemens EN100 Ethernet Modules
CVE-2019-13943

6.1MEDIUM

Summary

A vulnerability has been discovered in Siemens EN100 Ethernet modules which may allow attackers to exploit the web interface for Cross-Site Scripting (XSS) attacks. This vulnerability affects several variants of the EN100 Ethernet module (including DNP3, IEC 61850, IEC104, Modbus TCP, and PROFINET IO) and does not require authentication for exploitation. If an attacker successfully modifies specific web page contents, the application could behave unpredictably for users, potentially leading to unauthorized access to read or alter application data. As of the advisory's release, there were no known public exploits for this vulnerability.

Affected Version(s)

EN100 Ethernet module DNP3 variant All versions

EN100 Ethernet module IEC 61850 variant All versions < V4.37

EN100 Ethernet module IEC104 variant All versions

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.