CVE-2011-4511: XSS
Cross-site scripting (XSS) vulnerability in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2008 before SP3; WinCC V11 (aka TIA portal) before SP2 Update 1; the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-4510.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-4511?
CVE-2011-4511 has been assigned a medium severity rating due to its potential to enable cross-site scripting attacks.
How do I fix CVE-2011-4511?
To fix CVE-2011-4511, users should apply the latest security updates provided by Siemens for affected versions of their software.
What versions of Siemens software are affected by CVE-2011-4511?
CVE-2011-4511 affects Siemens WinCC flexible versions 2004, 2005, 2007, 2008 before SP3, and WinCC V11 before SP2 Update 1, among others.
What type of vulnerability is CVE-2011-4511?
CVE-2011-4511 is classified as a cross-site scripting (XSS) vulnerability.
Are there any known exploits for CVE-2011-4511?
As of now, there are no publicly known exploits specifically targeting CVE-2011-4511, but the vulnerability still poses a risk if unpatched.