CVE-2019-10933
Published on: 07/11/2019 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:27:39 PM UTC
Certain versions of Spectrum Power 3 from Siemens contain the following vulnerability:
A vulnerability has been identified in Spectrum Power 3 (Corporate User Interface) (All versions <= v3.11), Spectrum Power 4 (Corporate User Interface) (Version v4.75), Spectrum Power 5 (Corporate User Interface) (All versions < v5.50), Spectrum Power 7 (Corporate User Interface) (All versions <= v2.20). The web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user does not need to be logged into the web interface in order for the exploitation to succeed.At the stage of publishing this security advisory no public exploitation is known.
- CVE-2019-10933 has been assigned by
productc[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Siemens AG - Spectrum Power 3 (Corporate User Interface) version All versions <= v3.11
- Affected Vendor/Software:
Siemens AG - Spectrum Power 4 (Corporate User Interface) version Version v4.75
- Affected Vendor/Software:
Siemens AG - Spectrum Power 5 (Corporate User Interface) version All versions < v5.50
- Affected Vendor/Software:
Siemens AG - Spectrum Power 7 (Corporate User Interface) version All versions <= v2.20
CVSS3 Score: 6.1 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | LOW | LOW | NONE |
CVSS2 Score: 4.3 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | PARTIAL | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Vendor Advisory cert-portal.siemens.com application/pdf |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Siemens | Spectrum Power 3 | All | All | All | All |
Application | Siemens | Spectrum Power 4 | All | All | All | All |
Application | Siemens | Spectrum Power 5 | All | All | All | All |
Application | Siemens | Spectrum Power 7 | All | All | All | All |
- cpe:2.3:a:siemens:spectrum_power_3:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:spectrum_power_4:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:spectrum_power_5:*:*:*:*:*:*:*:*:
- cpe:2.3:a:siemens:spectrum_power_7:*:*:*:*:*:*:*:*: