Cross-Site Scripting Vulnerability in Siemens SICAM Products
CVE-2020-10043

6.1MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
14 July 2020

Summary

A Cross-Site Scripting (XSS) vulnerability has been detected in Siemens SICAM products, including SICAM MMU, SICAM SGU, and SICAM T. This weakness occurs when the web server inadvertently allows malicious links to exploit unsuspecting users. If users are tricked into clicking these links, it can result in unauthorized actions being executed within the safety of the user's session. All versions of SICAM MMU earlier than V2.05, SICAM SGU, and SICAM T prior to V2.18 are susceptible to this issue, posing a potential risk to user data and system integrity.

Affected Version(s)

SICAM MMU All versions < V2.05

SICAM SGU All versions

SICAM T All versions < V2.18

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.