CVE-2016-1488
6.1
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
Cross-site scripting (XSS) vulnerability in the login form in the integrated web server on Siemens OZW OZW672 devices before 6.00 and OZW772 devices before 6.00 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected (2)
Products: Siemens: Ozw672 Firmware, Ozw772 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ozw672 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 5.2 |
| Running on/with | Platform Versions |
|---|---|
Siemens Ozw772 | All versions |
References (4)
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.