MEDIUM · 5.4

CVE-2018-16555

A vulnerability has been identified in SCALANCE S602 (All versions < V4.0.1.1), SCALANCE S612 (All versions < V4.0.1.1), SCALANCE S623 (All versions < V4.0.1.1), SCALANCE S627-2M (All versions < V4.0....

Vulnerability Description

A vulnerability has been identified in SCALANCE S602 (All versions < V4.0.1.1), SCALANCE S612 (All versions < V4.0.1.1), SCALANCE S623 (All versions < V4.0.1.1), SCALANCE S627-2M (All versions < V4.0.1.1). The integrated web server could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user must be logged into the web interface in order for the exploitation to succeed. At the stage of publishing this security advisory no public exploitation is known.

CVSS Score

5.4

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
SiemensScalance S602 Firmware< v4.0.1.1
SiemensScalance S602-
SiemensScalance S612 Firmware< 4.0.1.1
SiemensScalance S612-
SiemensScalance S623 Firmware< 4.0.1.1
SiemensScalance S623-
SiemensScalance S627-2M Firmware< 4.0.1.1
SiemensScalance S627-2M-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-16555?

CVE-2018-16555 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A vulnerability has been identified in SCALANCE S602 (All versions < V4.0.1.1), SCALANCE S612 (All versions < V4.0.1.1), SCALANCE S623 (All versions < V4.0.1.1), SCALANCE S627-2M (All versions < V4.0....

How severe is CVE-2018-16555?

CVE-2018-16555 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-16555?

Check the references section above for vendor advisories and patch information. Affected products include: Siemens Scalance S602 Firmware, Siemens Scalance S602, Siemens Scalance S612 Firmware, Siemens Scalance S612, Siemens Scalance S623 Firmware.