CVE-2020-7575 is a persistent cross-site scripting (XSS) vulnerability affecting Siemens Climatix POL908 (all versions) and POL909 (versions prior to V11.32) BACnet/IP and AWM modules. An unauthenticated attacker with network access can inject malicious JavaScript into the web server's access logs via specially crafted GET requests. When a privileged user later views these logs, the injected code could execute, potentially compromising the confidentiality and integrity of their web session. While the CVSS score is 6.1 (Medium), indicating a relatively low complexity attack, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:siemens:climatix_pol908_firmware:*:*:*:*:*:*:*:* | ||
< 11.32CPE matchmatch criteria | cpe:2.3:o:siemens:climatix_pol909_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.