First published: Thu Mar 21 2013(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the HMI web application in Siemens WinCC (TIA Portal) 11 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens TIA Portal | =11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0668 is classified as a high-severity vulnerability due to its potential to allow remote attackers to execute arbitrary scripts.
To fix CVE-2013-0668, update Siemens WinCC (TIA Portal) to the latest version or apply the recommended patches released by Siemens.
CVE-2013-0668 allows for cross-site scripting (XSS) attacks, enabling attackers to inject malicious web scripts into the application.
CVE-2013-0668 specifically affects Siemens WinCC (TIA Portal) version 11.0.
Using Siemens WinCC version 11.0 is not safe until it has been updated or patched to mitigate the risks associated with CVE-2013-0668.