First published: Wed Mar 29 2017(Updated: )
The integrated web server in Siemens RUGGEDCOM ROX I (all versions) at port 10000/TCP could allow an authenticated user to perform stored Cross-Site Scripting attacks.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens ROX I OS | <=2.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6864 has a medium severity rating as it allows for stored Cross-Site Scripting attacks under certain conditions.
To fix CVE-2017-6864, ensure that you apply all available security updates to Siemens RUGGEDCOM ROX I firmware.
CVE-2017-6864 affects all versions of Siemens RUGGEDCOM ROX I up to and including version 2.9.0.
No, CVE-2017-6864 can only be exploited by authenticated users.
CVE-2017-6864 is associated with stored Cross-Site Scripting (XSS) attacks.