Cross-Site Scripting Vulnerability in Siemens EN100 Ethernet Modules
CVE-2019-13943
Key Information:
- Vendor
- Siemens Ag
- Status
- Vendor
- CVE Published:
- 12 December 2019
Summary
A vulnerability has been discovered in Siemens EN100 Ethernet modules which may allow attackers to exploit the web interface for Cross-Site Scripting (XSS) attacks. This vulnerability affects several variants of the EN100 Ethernet module (including DNP3, IEC 61850, IEC104, Modbus TCP, and PROFINET IO) and does not require authentication for exploitation. If an attacker successfully modifies specific web page contents, the application could behave unpredictably for users, potentially leading to unauthorized access to read or alter application data. As of the advisory's release, there were no known public exploits for this vulnerability.
Affected Version(s)
EN100 Ethernet module DNP3 variant All versions
EN100 Ethernet module IEC 61850 variant All versions < V4.37
EN100 Ethernet module IEC104 variant All versions
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved