PT-2023-3377 · Siemens · Power Meter Sicam Q100+1
Published
2023-06-13
·
Updated
2024-01-09
·
CVE-2023-30901
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
POWER METER SICAM Q100 versions prior to V2.60
POWER METER SICAM Q200 (affected versions not specified)
Description
A vulnerability has been identified in the web interface of the affected devices, making them vulnerable to Cross-Site Request Forgery attacks. By tricking an authenticated victim user into clicking a malicious link, an attacker could perform arbitrary actions on the device on behalf of the victim user. The issue is related to the exploitation of the web interface, allowing a remote attacker to execute arbitrary actions.
Recommendations
For POWER METER SICAM Q100 versions prior to V2.60, update to version V2.60 or later to resolve the issue.
For POWER METER SICAM Q200, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Power Meter Sicam Q100
Power Meter Sicam Q200