MEDIUM · 6.5

CVE-2018-13810

A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). The integrated configuration web server of the affected CP devices could allow a Cross-Site Request Forgery (CSRF...

Vulnerability Description

A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). The integrated configuration web server of the affected CP devices could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requires user interaction by a legitimate user. A successful attack could allow an attacker to trigger actions via the web interface that the legitimate user is allowed to perform. At the time of advisory publication no public exploitation of this vulnerability was known.

CVSS Score

6.5

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
SiemensCp 1604 Firmware<= 2.8
SiemensCp 1604-
SiemensCp 1616 Firmware<= 2.8
SiemensCp 1616-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-13810?

CVE-2018-13810 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A vulnerability has been identified in CP 1604 (All versions), CP 1616 (All versions). The integrated configuration web server of the affected CP devices could allow a Cross-Site Request Forgery (CSRF...

How severe is CVE-2018-13810?

CVE-2018-13810 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-13810?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Cp 1604 Firmware, Siemens Cp 1604, Siemens Cp 1616 Firmware, Siemens Cp 1616.