Cross-Site Scripting Flaw in Spectrum Power 4 by Siemens
CVE-2022-23312

6.1MEDIUM

Key Information:

Vendor
Siemens
Vendor
CVE Published:
9 February 2022

Summary

A Cross-Site Scripting (XSS) vulnerability has been discovered in the 'Online Help' component of Siemens Spectrum Power 4. This flaw allows attackers to exploit the web application by tricking users into clicking on malicious links, potentially leading to unauthorized access or data manipulation. Versions prior to V4.70 SP9 Security Patch 1 are affected, emphasizing the importance of applying the necessary updates to mitigate risks.

Affected Version(s)

Spectrum Power 4 All versions < V4.70 SP9 Security Patch 1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.