CVE-2018-16555
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability has been identified in SCALANCE S602 (All versions < V4.0.1.1), SCALANCE S612 (All versions < V4.0.1.1), SCALANCE S623 (All versions < V4.0.1.1), SCALANCE S627-2M (All versions < V4.0.1.1). The integrated web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user must be logged into the web interface in order for the exploitation to succeed. At the stage of publishing this security advisory no public exploitation is known.
Se ha identificado una vulnerabilidad en SCALANCE S602 (todas las versiones anteriores a la V4.0.1.1), SCALANCE S612 (todas las versiones anteriores a la V4.0.1.1), SCALANCE S623 (todas las versiones anteriores a la V4.0.1.1), SCALANCE S627-2M (todas las versiones anteriores a la V4.0.1.1). El servidor web integrado podría permitir ataques Cross-Site Scripting (XSS) si los usuarios incautos son engañados para que accedan a un enlace malicioso. Se necesita interacción del usuario para explotar esta vulnerabilidad con éxito. El usuario debe haber iniciado sesión en la interfaz web para que la explotación tenga éxito. En el momento de publicación de este aviso de seguridad, no se conoce ninguna explotación pública.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-09-06 CVE Reserved
- 2018-12-13 CVE Published
- 2024-08-05 CVE Updated
- 2024-10-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/105937 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-242982.pdf | 2019-10-09 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Siemens Search vendor "Siemens" | Scalance S602 Firmware Search vendor "Siemens" for product "Scalance S602 Firmware" | < v4.0.1.1 Search vendor "Siemens" for product "Scalance S602 Firmware" and version " < v4.0.1.1" | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance S602 Search vendor "Siemens" for product "Scalance S602" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Scalance S612 Firmware Search vendor "Siemens" for product "Scalance S612 Firmware" | < 4.0.1.1 Search vendor "Siemens" for product "Scalance S612 Firmware" and version " < 4.0.1.1" | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance S612 Search vendor "Siemens" for product "Scalance S612" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Scalance S623 Firmware Search vendor "Siemens" for product "Scalance S623 Firmware" | < 4.0.1.1 Search vendor "Siemens" for product "Scalance S623 Firmware" and version " < 4.0.1.1" | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance S623 Search vendor "Siemens" for product "Scalance S623" | - | - |
Safe
|
Siemens Search vendor "Siemens" | Scalance S627-2m Firmware Search vendor "Siemens" for product "Scalance S627-2m Firmware" | < 4.0.1.1 Search vendor "Siemens" for product "Scalance S627-2m Firmware" and version " < 4.0.1.1" | - |
Affected
| in | Siemens Search vendor "Siemens" | Scalance S627-2m Search vendor "Siemens" for product "Scalance S627-2m" | - | - |
Safe
|