VDB

GCVE-110-NCSC-2026-112

GCVE-110-NCSC-2026-112
Advisory PublishedCVSS 6.5/10
Vulnetix · Advisory published April 14, 2026
Affected devices improperly sanitize user input in their web interface, enabling an authenticated remote attacker with administrative privileges to execute a DOM-based cross-site scripting (XSS) attack.

Weaknesses (CWE)

CWE-306Missing Authentication for Critical FunctionCWE-829Inclusion of Functionality from Untrusted Control SphereCWE-346Origin Validation ErrorCWE-863Incorrect AuthorizationCWE-290Authentication Bypass by SpoofingCWE-307Improper Restriction of Excessive Authentication AttemptsCWE-125Out-of-bounds ReadCWE-835Loop with Unreachable Exit Condition ('Infinite Loop')CWE-862Missing AuthorizationCWE-770Allocation of Resources Without Limits or ThrottlingCWE-80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)CWE-197Numeric Truncation ErrorCWE-295Improper Certificate ValidationCWE-347Improper Verification of Cryptographic SignatureCWE-639Authorization Bypass Through User-Controlled KeyCWE-266Incorrect Privilege AssignmentCWE-305Authentication Bypass by Primary Weakness

Risk Scores

CVSS 3.1
6.5/10
Medium · CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C

Affected Products

VendorProductVersionsPlatforms
Siemensvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

73,873 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›