PT-2018-2978 · Siemens · Cp 1616+1

Publicado

2018-01-08

·

Atualizado

2019-07-11

·

CVE-2018-13809

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CP 1604 (All versions) CP 1616 (All versions)
Description A vulnerability has been identified that could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into following a malicious link. User interaction is required for a successful exploitation. The issue is related to the lack of protection measures for the web page structure. At the time of advisory publication, no public exploitation of this issue was known.
Recommendations For CP 1604 (All versions), consider implementing additional security measures to protect against Cross-Site Scripting attacks, such as validating user input and implementing web application firewalls. For CP 1616 (All versions), consider implementing additional security measures to protect against Cross-Site Scripting attacks, such as validating user input and implementing web application firewalls. As a temporary workaround, consider restricting access to the integrated web server of the affected CP devices to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-03004
CVE-2018-13809

Produtos afetados

Cp 1604
Cp 1616