ZDI-CAN-19823: ZDI-23-1600: Siemens SINEMA Server sysLocation Cross-Site Scripting Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens SINEMA Server. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2023-35796.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19823?
The severity of ZDI-CAN-19823 is critical as it allows remote attackers to execute arbitrary code on affected installations.
How do I fix ZDI-CAN-19823?
To fix ZDI-CAN-19823, you should apply the latest security patches released by Siemens for SINEMA Server.
Who is affected by ZDI-CAN-19823?
ZDI-CAN-19823 affects installations of Siemens SINEMA Server SP3.
What type of attack is ZDI-CAN-19823?
ZDI-CAN-19823 is a remote code execution vulnerability that requires user interaction to exploit.
What are the risks associated with ZDI-CAN-19823?
The risks associated with ZDI-CAN-19823 include unauthorized access and control of the affected server by malicious attackers.