Vulnerability Details CVE-2019-6585
A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCALANCE S623 (All versions >= V3.0 and < V4.1), SCALANCE S627-2M (All versions >= V3.0 and < V4.1). The integrated configuration web server of the affected devices could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user must be logged into the web interface in order for the exploitation to succeed.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 53.2%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 4.3
Products affected by CVE-2019-6585
-
cpe:2.3:h:siemens:scalance_s602:-
-
cpe:2.3:h:siemens:scalance_s612:-
-
cpe:2.3:h:siemens:scalance_s623:-
-
cpe:2.3:h:siemens:scalance_s627-2m:-
-
cpe:2.3:o:siemens:scalance_s602_firmware:3.0
-
cpe:2.3:o:siemens:scalance_s602_firmware:4.0.1.1
-
cpe:2.3:o:siemens:scalance_s612_firmware:3.0
-
cpe:2.3:o:siemens:scalance_s612_firmware:4.0.1.1
-
cpe:2.3:o:siemens:scalance_s623_firmware:3.0
-
cpe:2.3:o:siemens:scalance_s623_firmware:4.0.1.1
-
cpe:2.3:o:siemens:scalance_s627-2m_firmware:3.0
-
cpe:2.3:o:siemens:scalance_s627-2m_firmware:4.0.1.1