CVE-2020-15781
CVE-2020-15781
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.0%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
14 Aug 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A vulnerability has been identified in SICAM WEB firmware for SICAM A8000 RTUs (All versions < V05.30). The login screen does not sufficiently sanitize input, which enables an attacker to generate specially crafted log messages. If an unsuspecting victim views the log messages via the web browser, these log messages might be interpreted and executed as code by the web application. This Cross-Site-Scripting (XSS) vulnerability might compromize the confidentiality, integrity and availability of the web application.
Affected products
Siemens AG · SICAM WEB firmware for SICAM A8000 RTUsWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →