Medium severity6.1NVD Advisory· Published Nov 15, 2017· Updated May 13, 2026
CVE-2017-12738
CVE-2017-12738
Description
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The integrated web server (port 80/tcp) of the affected devices could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into clicking on a malicious link.
Affected products
1- N/a/Siemens Sicam Rtus Sm 2556 Com Modules With The Firmware Variants Enos00, Erac00, Eta2, Etls00, Modi00, And Dnpi00v5Range: Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.securityfocus.com/bid/101884nvdThird Party AdvisoryVDB Entry
- www.siemens.com/cert/pool/cert/siemens_security_advisory_ssa-164516.pdfnvdMitigationVendor Advisory
News mentions
0No linked articles in our index yet.