Psi Gridconnect Gmbh · Smart Telecontrol Unit Tcg · CVE-2019-6528
**Name of the Vulnerable Software and Affected Versions**
PSI GridConnect GmbH Telecontrol Gateway and Smart Telecontrol Unit family, IEC104 Security Proxy versions
Telecontrol Gateway 3G versions 4.2.21 through 6.0.16 and prior
Telecontrol Gateway XS-MU versions 4.2.21 through 6.0.16 and prior
Telecontrol Gateway VM versions 4.2.21 through 6.0.16 and prior
Smart Telecontrol Unit TCG versions 5.0.27 through 6.0.16 and prior
IEC104 Security Proxy versions prior to 2.2.10
**Description**
The web application browser interprets input as active HTML, JavaScript, or VBScript, which could allow an attacker to execute arbitrary code.
**Recommendations**
For Telecontrol Gateway 3G versions 4.2.21 through 6.0.16 and prior, update to a version later than 6.0.16.
For Telecontrol Gateway XS-MU versions 4.2.21 through 6.0.16 and prior, update to a version later than 6.0.16.
For Telecontrol Gateway VM versions 4.2.21 through 6.0.16 and prior, update to a version later than 6.0.16.
For Smart Telecontrol Unit TCG versions 5.0.27 through 6.0.16 and prior, update to a version later than 6.0.16.
For IEC104 Security Proxy versions prior to 2.2.10, update to a version later than 2.2.10.