ZeroHour

CVE-2019-6585

CVSS 3.1
6.1 medium
EPSS
<1%p52
Published
()
Modified
Description

A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and = V3.0 and = V3.0 and = V3.0 and < V4.1). The integrated configuration web server of the affected devices could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user must be logged into the web interface in order for the exploitation to succeed.

Vendors
siemens
Products
scalance s602 firmware, scalance s612 firmware, scalance s623 firmware, scalance s627-2m firmware
Weakness
CWE-80, CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.