Vulnerability Description
A vulnerability was discovered in Siemens XHQ server 4 and 5 (4 before V4.7.1.3 and 5 before V5.0.0.2) that could allow an authenticated low-privileged remote user to gain read access to data in the XHQ solution exceeding his configured permission level.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Xhq Server | <= 4.7.1.2 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/99247Third Party AdvisoryVDB Entry
- https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-945660.pdfVendor Advisory
- http://www.securityfocus.com/bid/99247Third Party AdvisoryVDB Entry
- https://www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-945660.pdfVendor Advisory
FAQ
What is CVE-2017-6866?
CVE-2017-6866 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability was discovered in Siemens XHQ server 4 and 5 (4 before V4.7.1.3 and 5 before V5.0.0.2) that could allow an authenticated low-privileged remote user to gain read access to data in the X...
How severe is CVE-2017-6866?
CVE-2017-6866 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-6866?
Check the references section above for vendor advisories and patch information. Affected products include: Siemens Xhq Server.