QID 591376
Date Published: 2023-04-03
QID 591376: Siemens Climatix POL909 Cross-Site Scripting (XSS), Improper Access Control Multiple Vulnerabilities (SSA-252466, ICSA-22-069-07)
AFFECTED PRODUCTS
Climatix POL909 (AWM module): All versions prior to V11.36
QID Detection Logic:
This QID checks for the Vulnerable version of Siemens Climatix POL909 using passive scanning.
Successful exploitation of these vulnerabilities could allow an unauthenticated attacker to hijack and redirect users to a malicious webpage or allow an authenticated attacker to access sensitive files.
Solution
Customers are advised to refer to CERT MITIGATIONS section ETN-SB-2015-1000 for affected packages and patching details.
Vendor References
CVEs related to QID 591376
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ssa-252466 |
|