CVE-2020-15781

CRITICAL

SICAM A8000 Firmware < 05.30 - Stored Cross-Site Scripting via Login Screen Log Messages

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in SICAM WEB firmware for SICAM A8000 RTUs (All versions < V05.30). The login screen does not sufficiently sanitize input, which enables an attacker to generate specially crafted log messages. If an unsuspecting victim views the log messages via the web browser, these log messages might be interpreted and executed as code by the web application. This Cross-Site-Scripting (XSS) vulnerability might compromize the confidentiality, integrity and availability of the web application.

References (1)

Core 1
Core References
Mitigation, Patch, Vendor Advisory x_refsource_misc
https://cert-portal.siemens.com/productcert/pdf/ssa-370042.pdf

Scores

CVSS v3 9.6
EPSS 0.0050
EPSS Percentile 66.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-79
Status published
Products (1)
siemens/sicam_a8000_firmware < 05.30
Published Aug 14, 2020
Tracked Since Feb 18, 2026