Publication Date: 2020-12-08
Last Update: 2020-12-08
Current Version: V1.0
CVSS v3.1 Base Score: 8.1

Affected Product and Versions Remediation
XHQ:
All Versions < 6.1
Update to V6.1 or later, or apply recommentations from section Workarounds and Mitigations
Please call your local service organization for further information on how to obtain the new version of XHQ. If assistance in identifying your local service organization is required, please call a local Siemens hotline center: https://w3.siemens.com/aspa_app/

CVSS v3.1 Base Score 5.3
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
CWE: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVSS v3.1 Base Score 6.3
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N/E:P/RL:O/RC:C
CWE: CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)

CVSS v3.1 Base Score 6.3
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N/E:P/RL:O/RC:C
CWE: CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)

CVSS v3.1 Base Score 7.2
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-89: Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’)

CVSS v3.1 Base Score 6.5
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C
CWE: CWE-23: Relative Path Traversal

CVSS v3.1 Base Score 7.1
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N/E:P/RL:O/RC:C
CWE: CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)

CVSS v3.1 Base Score 8.1
CVSS Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N/E:P/RL:O/RC:C
CWE: CWE-352: Cross-Site Request Forgery (CSRF)

https://www.siemens.com/cert/advisories