A vulnerability has been identified in IE/WSN-PA Link WirelessHART Gateway (All versions). The integrated configuration web server of the affected device could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user must be logged into the web interface in order for the exploitation to succeed. At the stage of publishing this security advisory no public exploitation is known.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HSiemens Ie\/wsn Pa Link Wirelesshart Gateway
HWSiemensall versionsSiemens Ie\/wsn Pa Link Wirelesshart Gateway Firmware
OSSiemensall versions
Related vulnerabilities
Buffer overflow RCE z uprawnieniami root w PAN-OS Captive Portal
Fortinet – Auth Bypass przez FortiCloud SSO w wielu produktach
Fortinet FortiOS/FortiProxy/FortiSwitchManager — Auth Bypass przez SAML
Spring4Shell — RCE przez data binding w Spring MVC/WebFlux na JDK 9+
Apache Log4j: niekompletna naprawa CVE-2021-44228 — RCE przez JNDI Lookup