A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCALANCE S623 (All versions >= V3.0 and < V4.1), SCALANCE S627-2M (All versions >= V3.0 and < V4.1). The integrated configuration web server of the affected devices could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user must be logged into the web interface in order for the exploitation to succeed.
2020-03-10T20:15:20.257
2024-11-21T04:46:45.233
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | siemens | scalance_s602_firmware | < 4.1 | Yes |
Hardware | siemens | scalance_s602 | - | No |
Operating System | siemens | scalance_s612_firmware | < 4.1 | Yes |
Hardware | siemens | scalance_s612 | - | No |
Operating System | siemens | scalance_s623_firmware | < 4.1 | Yes |
Hardware | siemens | scalance_s623 | - | No |
Operating System | siemens | scalance_s627-2m_firmware | < 4.1 | Yes |
Hardware | siemens | scalance_s627-2m | - | No |