CVE-2020-15781 - CVE House
Back to Database
Status published Critical CVE-2020-15781

A vulnerability has been identified in SICAM WEB firmware for...

Vulnerability Description

A vulnerability has been identified in SICAM WEB firmware for SICAM A8000 RTUs (All versions < V05.30). The login screen does not sufficiently sanitize input, which enables an attacker to generate specially crafted log messages. If an unsuspecting victim views the log messages via the web browser, these log messages might be interpreted and executed as code by the web application. This Cross-Site-Scripting (XSS) vulnerability might compromize the confidentiality, integrity and availability of the web application.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-15781

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

SICAM WEB firmware for SICAM A8000 RTUs
Vulnerable Versions:
All versions < V05.30

Timeline

Official Publish: August 14th, 2020
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Weaknesses (CWE)