PT-2020-14627 · Siemens · Sicam Web

Published

2020-08-14

·

Updated

2020-08-21

·

CVE-2020-15781

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SICAM WEB firmware for SICAM A8000 RTUs versions prior to V05.30
Description A Cross-Site-Scripting (XSS) issue has been identified, where the login screen does not sufficiently sanitize input. This allows an attacker to generate specially crafted log messages. If an unsuspecting victim views these log messages via the web browser, they might be interpreted and executed as code by the web application, potentially compromising the confidentiality, integrity, and availability of the web application.
Recommendations For versions prior to V05.30, update to version V05.30 or later to resolve the issue. As a temporary workaround, consider restricting access to the login screen and log messages to minimize the risk of exploitation. Avoid viewing log messages via the web browser until the issue is resolved.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15781

Affected Products

Sicam Web