CVE-2020-15781: XSS
A vulnerability has been identified in SICAM WEB firmware for SICAM A8000 RTUs (All versions < V05.30). The login screen does not sufficiently sanitize input, which enables an attacker to generate specially crafted log messages. If an unsuspecting victim views the log messages via the web browser, these log messages might be interpreted and executed as code by the web application. This Cross-Site-Scripting (XSS) vulnerability might compromize the confidentiality, integrity and availability of the web application.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2020-15781?
CVE-2020-15781 is classified as a medium severity vulnerability.
How do I fix CVE-2020-15781?
To mitigate CVE-2020-15781, upgrade the SICAM A8000 RTU firmware to version 05.30 or later.
What types of devices are affected by CVE-2020-15781?
CVE-2020-15781 affects all versions of SICAM WEB firmware for SICAM A8000 RTUs prior to version 05.30.
What attack vector is associated with CVE-2020-15781?
CVE-2020-15781 can be exploited through the improperly sanitized login screen leading to crafted log message vulnerabilities.
What makes CVE-2020-15781 dangerous?
CVE-2020-15781 can lead to log injection attacks, potentially compromising the confidentiality and integrity of log data.