CVE-2013-0672: XSS
Published Mar 21, 2013
·Updated
Cross-site scripting (XSS) vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remote authenticated users to inject arbitrary web script or HTML via unspecified data.
Affected Software
1 affected component
Siemens Wincc Tia Portal=11.0
Event History
Mar 21, 2013
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-0672?
CVE-2013-0672 is considered a medium severity vulnerability due to its potential for cross-site scripting attacks.
2
How do I fix CVE-2013-0672?
To fix CVE-2013-0672, update Siemens WinCC (TIA Portal) to the latest patched version provided by Siemens.
3
What is the nature of the vulnerability in CVE-2013-0672?
CVE-2013-0672 is a cross-site scripting (XSS) vulnerability that allows authenticated users to inject web scripts or HTML.
4
Who is affected by CVE-2013-0672?
CVE-2013-0672 affects users of Siemens WinCC (TIA Portal) version 11.0.
5
Can CVE-2013-0672 be exploited remotely?
Yes, CVE-2013-0672 can be exploited remotely by authenticated users who can inject malicious scripts.