CVE-2011-4510: XSS
Cross-site scripting (XSS) vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-4511.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4510?
CVE-2011-4510 has a moderate severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2011-4510?
To fix CVE-2011-4510, you need to apply the latest patches or updates provided by Siemens for affected versions of WinCC flexible and WinCC.
What versions are affected by CVE-2011-4510?
CVE-2011-4510 affects Siemens WinCC flexible versions 2004 to 2008 and WinCC V11 prior to SP2 Update 1.
Can CVE-2011-4510 be exploited remotely?
Yes, CVE-2011-4510 can be exploited remotely, allowing attackers to execute scripts in the context of the affected web server.
Is it safe to use Siemens WinCC flexible versions prior to SP3 if not patched for CVE-2011-4510?
Using Siemens WinCC flexible versions prior to SP3 without patching for CVE-2011-4510 poses a security risk and should be avoided.