CVE Published: 08/10/2024 |
CVE Updated: 12/11/2024 |
CVE Year: 2024 Source: siemens |
Vendor: Siemens |
Product: SIMATIC Drive Controller CPU 1504D TF Status : PUBLISHED
CVE-2024-46886 Description
The web server of affected devices does not properly validate input that is used for a user redirection. This could allow an attacker to make the server redirect the legitimate user to an attacker-chosen URL. For a successful exploit, the legitimate user must actively click on an attacker-crafted link.
Metrics
CVSS Version: 3.1 |
Base Score: 4.7 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N/E:P/RL:O/RC:C