Cross-Site Scripting Vulnerability in Siemens SICAM Products
CVE-2020-10043
6.1MEDIUM
Summary
A Cross-Site Scripting (XSS) vulnerability has been detected in Siemens SICAM products, including SICAM MMU, SICAM SGU, and SICAM T. This weakness occurs when the web server inadvertently allows malicious links to exploit unsuspecting users. If users are tricked into clicking these links, it can result in unauthorized actions being executed within the safety of the user's session. All versions of SICAM MMU earlier than V2.05, SICAM SGU, and SICAM T prior to V2.18 are susceptible to this issue, posing a potential risk to user data and system integrity.
Affected Version(s)
SICAM MMU All versions < V2.05
SICAM SGU All versions
SICAM T All versions < V2.18
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved