Publication Date: 2019-12-10
Last Update: 2019-12-10
Current Version: V1.0
CVSS v3.1 Base Score: 8.8

Affected Product and Versions Remediation
XHQ:
All versions < V6.0.0.2

Update to V6.0.0.2 or later


Please call your local service organization for further information on how to obtain the new version of XHQ. If assistance in identifying your local service organization is required, please call a local Siemens hotline center: https://w3.siemens.com/aspa_app/

CVSS v3.1 Base Score 8.1
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C
CWE: CWE-352: Cross-Site Request Forgery (CSRF)

CVSS v3.1 Base Score 6.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CVSS v3.1 Base Score 8.8
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-20: Improper Input Validation

https://www.siemens.com/cert/advisories