Stored Cross-Site Scripting Flaw in SIMATIC PCS neo by Siemens
CVE-2023-46099
4.8MEDIUM
Summary
A stored cross-site scripting vulnerability has been discovered in the Administration Console of SIMATIC PCS neo. This security flaw affects all versions prior to V4.1 and allows an attacker with elevated privileges to inject malicious JavaScript code into the application. The injected code can then be executed by another user, potentially compromising sensitive information and endangering system integrity.
Affected Version(s)
SIMATIC PCS neo All versions < V4.1
References
CVSS V3.1
Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved