PT-2018-2978 · Siemens · Cp 1616+1

Published

2018-01-08

·

Updated

2019-07-11

·

CVE-2018-13809

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CP 1604 (All versions) CP 1616 (All versions)
Description A vulnerability has been identified that could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into following a malicious link. User interaction is required for a successful exploitation. The issue is related to the lack of protection measures for the web page structure. At the time of advisory publication, no public exploitation of this issue was known.
Recommendations For CP 1604 (All versions), consider implementing additional security measures to protect against Cross-Site Scripting attacks, such as validating user input and implementing web application firewalls. For CP 1616 (All versions), consider implementing additional security measures to protect against Cross-Site Scripting attacks, such as validating user input and implementing web application firewalls. As a temporary workaround, consider restricting access to the integrated web server of the affected CP devices to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03004
CVE-2018-13809

Affected Products

Cp 1604
Cp 1616