PT-2023-3377 · Siemens · Power Meter Sicam Q100+1

Published

2023-06-13

·

Updated

2024-01-09

·

CVE-2023-30901

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions POWER METER SICAM Q100 versions prior to V2.60 POWER METER SICAM Q200 (affected versions not specified)
Description A vulnerability has been identified in the web interface of the affected devices, making them vulnerable to Cross-Site Request Forgery attacks. By tricking an authenticated victim user into clicking a malicious link, an attacker could perform arbitrary actions on the device on behalf of the victim user. The issue is related to the exploitation of the web interface, allowing a remote attacker to execute arbitrary actions.
Recommendations For POWER METER SICAM Q100 versions prior to V2.60, update to version V2.60 or later to resolve the issue. For POWER METER SICAM Q200, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03541
CVE-2023-30901

Affected Products

Power Meter Sicam Q100
Power Meter Sicam Q200