Severity
Medium
Analysis summary
An attacker sending a malicious link to an unsuspecting user may be able to execute a cross-site scripting attack, which may allow information disclosure, code execution, or denial-of-service.
Impact
- Information disclosure
- Denial of service
Affected Vendors
Siemens
Affected Products
IE/WSN-PA Link WirelessHART Gateway all versions
Remediation
Siemens has identified the following specific workarounds and mitigations that users can apply to reduce the risk:
- Only access links from trusted sources in the browser used to configure IE/WSN-PA Link.