CVE-2016-1488: XSS
Published Jan 30, 2016
·Updated
Cross-site scripting (XSS) vulnerability in the login form in the integrated web server on Siemens OZW OZW672 devices before 6.00 and OZW772 devices before 6.00 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Affected Software
4 affected components
Siemens OZW672
Siemens Ozw672 Firmware<=5.2
Siemens OZW772
Siemens Ozw772 Firmware<=5.2
Event History
Jan 30, 2016
CVE Published
via MITRE·11:00 AM
Data Sourced
via MITRE·11:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-1488?
CVE-2016-1488 is considered a high severity cross-site scripting vulnerability.
2
How do I fix CVE-2016-1488?
To fix CVE-2016-1488, upgrade the firmware of Siemens OZW672 and OZW772 devices to version 6.00 or later.
3
Which devices are affected by CVE-2016-1488?
CVE-2016-1488 affects Siemens OZW672 and OZW772 devices with firmware versions up to 5.2.
4
What type of attack can exploit CVE-2016-1488?
CVE-2016-1488 can be exploited through cross-site scripting (XSS) attacks via a crafted URL.
5
Can CVE-2016-1488 be exploited remotely?
Yes, CVE-2016-1488 allows remote attackers to exploit the vulnerability through the integrated web server.