CVE-2019-10933 is a Cross-Site Scripting (XSS) vulnerability affecting the Corporate User Interface of Siemens Spectrum Power 3, 4, 5, and 7. This medium-severity vulnerability (CVSS 6.1) allows an attacker to execute malicious scripts if an unsuspecting user is tricked into clicking a specially crafted link, even without being logged in. While user interaction is required, the attack complexity is low, potentially leading to limited confidentiality and integrity impacts. There is currently no known public exploitation, exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.11CPE matchmatch criteria | cpe:2.3:a:siemens:spectrum_power_3:*:*:*:*:*:*:*:* | ||
<= 4.75CPE matchmatch criteria | cpe:2.3:a:siemens:spectrum_power_4:*:*:*:*:*:*:*:* | ||
<= 5.50CPE matchmatch criteria | cpe:2.3:a:siemens:spectrum_power_5:*:*:*:*:*:*:*:* | ||
<= 2.20CPE matchmatch criteria | cpe:2.3:a:siemens:spectrum_power_7:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.