Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A vulnerability has been identified in SCALANCE X-200IRT switch family (incl. SIPLUS NET variants) (All versions < V5.4.1), SCALANCE X-200RNA switch family (All versions < V3.2.7), SCALANCE X-300 switch family (incl. X408 and SIPLUS NET variants) (All versions < V4.1.3). A remote, authenticated attacker with access to the configuration web server could be able to store script code on the web site, if the HRP redundancy option is set. This code could be executed in the web browser of victims visiting this web site (XSS), affecting its confidentiality, integrity and availability. User interaction is required for successful exploitation, as the user needs to visit the manipulated web site. At the stage of publishing this security advisory no public exploitation is known. The vendor has confirmed the vulnerability and provides mitigations to resolve it.
CVSS Information
N/A
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Vulnerability Title
Siemens SCALANCE X-200 IRT和SCALANCE X-300 跨站脚本漏洞
Vulnerability Description
Siemens Scalance X-200是德国西门子(Siemens)公司的一款工业级以太网交换机。 Siemens SCALANCE X-200 IRT 5.4.1之前版本和SCALANCE X-300中存在跨站脚本漏洞。远程攻击者可利用该漏洞向网站上存储脚本代码并在用户浏览器中执行该代码。
CVSS Information
N/A
Vulnerability Type
N/A