VDB
SSA-591405
SSA-591405
PUBLISHED
CVSS 7.5 HIGH
The integrated configuration web server of the affected devices could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user must be logged into the web interface in order for the exploitation to succeed.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | SCALANCE S623 | |
| Siemens | SCALANCE S612 | |
| Siemens | SCALANCE S602 | |
| Siemens | SCALANCE S627-2M |
Timeline
- Feb 11, 2020 CVE Published
- Apr 13, 2021 CVE Updated
References
- https://cert-portal.siemens.com/productcert/csaf/ssa-591405.json advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-591405.pdf advisory
- https://cert-portal.siemens.com/productcert/txt/ssa-591405.txt advisory
- https://cert-portal.siemens.com/productcert/mitre/CVE-2019-6585.json advisory
- https://cert-portal.siemens.com/productcert/mitre/CVE-2019-13925.json advisory
- https://cert-portal.siemens.com/productcert/mitre/CVE-2019-13926.json advisory