CVE-2019-6585
CVE-2019-6585
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.7%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
10 Mar 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCALANCE S623 (All versions >= V3.0 and < V4.1), SCALANCE S627-2M (All versions >= V3.0 and < V4.1). The integrated configuration web server of the affected devices could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user must be logged into the web interface in order for the exploitation to succeed.
Affected products
Siemens · SCALANCE S602Siemens · SCALANCE S612Siemens · SCALANCE S623Siemens · SCALANCE S627-2MWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →