Medium severity6.1NVD Advisory· Published Mar 10, 2020· Updated Jun 17, 2026
CVE-2019-6585
CVE-2019-6585
Description
A vulnerability has been identified in SCALANCE S602 (All versions >= V3.0 and < V4.1), SCALANCE S612 (All versions >= V3.0 and < V4.1), SCALANCE S623 (All versions >= V3.0 and < V4.1), SCALANCE S627-2M (All versions >= V3.0 and < V4.1). The integrated configuration web server of the affected devices could allow Cross-Site Scripting (XSS) attacks if unsuspecting users are tricked into accessing a malicious link. User interaction is required for a successful exploitation. The user must be logged into the web interface in order for the exploitation to succeed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
11- cpe:2.3:o:siemens:scalance_s602_firmware:*:*:*:*:*:*:*:*Range: >=3.0,<4.1
- cpe:2.3:o:siemens:scalance_s612_firmware:*:*:*:*:*:*:*:*Range: >=3.0,<4.1
- cpe:2.3:o:siemens:scalance_s623_firmware:*:*:*:*:*:*:*:*Range: >=3.0,<4.1
- cpe:2.3:o:siemens:scalance_s627-2m_firmware:*:*:*:*:*:*:*:*Range: >=3.0,<4.1
- Range: >=V3.0 and <V4.1
>=V3.0 and <V4.1+ 2 more
- (no CPE)range: >=V3.0 and <V4.1
- (no CPE)range: All versions >= V3.0 and < V4.1
- (no CPE)range: All versions >= V3.0 and < V4.1
>=V3.0 and <V4.1+ 1 more
- (no CPE)range: >=V3.0 and <V4.1
- (no CPE)range: All versions >= V3.0 and < V4.1
- Range: All versions >= V3.0 and < V4.1
Patches
Vulnerability mechanics
References
2- cert-portal.siemens.com/productcert/pdf/ssa-591405.pdfnvdVendor Advisory
- www.us-cert.gov/ics/advisories/icsa-20-042-10nvdThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.