Siemens gWAP
ICS-CERT Advisories·vor 13 d·Offiziell
View CSAF Summary Siemens gPROMS Web Applications Publisher (gWAP) is affected by a remote code execution vulnerability introduced through a third-party component, namely the Axios HTTP client library. The vulnerability stems from a specific "Gadget" attack chain that allows prototype pollution in other third-party libraries, potentially allowing an attacker to execute arbitrary code. Siemens has released a new version for gWAP and recommends to update to the latest version. The following versions of Siemens gWAP are affected: gWAP vers:intdot/<3.1.1 CVSS Vendor Equipment Vulnerabilities v3 8
Kategorien privacy · unknown-it-category-14
Originalquelle / Advisory ↗Veröffentlicht
14.5.2026, 12:00:00
Abgerufen
27.5.2026, 04:13:20
Trust
official · 100/100
Sprache
en