PT-2020-19636 · Siemens · Spectrum Power 5

Published

2020-03-10

·

Updated

2020-03-11

·

CVE-2020-7579

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Spectrum Power 5 versions prior to 5.50 HF02
Description A security issue has been identified that could allow Cross-Site Scripting (XSS) attacks. This occurs when unsuspecting users are tricked into accessing a malicious link, requiring user interaction for successful exploitation.
Recommendations For versions prior to 5.50 HF02, update to version 5.50 HF02 or later to resolve the issue. As a temporary workaround, consider restricting access to the web server to minimize the risk of exploitation. Avoid using links from untrusted sources to prevent potential attacks.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-7579

Affected Products

Spectrum Power 5