Cross-Site Scripting Flaw in Spectrum Power 4 by Siemens
CVE-2022-23312
6.1MEDIUM
Summary
A Cross-Site Scripting (XSS) vulnerability has been discovered in the 'Online Help' component of Siemens Spectrum Power 4. This flaw allows attackers to exploit the web application by tricking users into clicking on malicious links, potentially leading to unauthorized access or data manipulation. Versions prior to V4.70 SP9 Security Patch 1 are affected, emphasizing the importance of applying the necessary updates to mitigate risks.
Affected Version(s)
Spectrum Power 4 All versions < V4.70 SP9 Security Patch 1
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved