Cross-Site Scripting Vulnerability in RUGGEDCOM Products by Siemens
CVE-2021-37208
9.6CRITICAL
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 8 March 2022
Summary
An identified vulnerability within Siemens RUGGEDCOM products allows attackers with privileged access to execute cross-site scripting. This results from improper handling of special characters on the web server configuration page, which could lead to the exposure of sensitive information. Organizations utilizing these systems must implement mitigations to safeguard their network integrity.
Affected Version(s)
RUGGEDCOM i800 All versions < V4.3.8
RUGGEDCOM i800NC All versions < V4.3.8
RUGGEDCOM i801 All versions < V4.3.8
References
CVSS V3.1
Score:
9.6
Severity:
CRITICAL
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved