PT-2015-2585 · Allen Bradley · Allen-Bradley Micrologix 1400+1

Ilya Karpov

·

Publicado

2015-10-28

·

Atualizado

2015-10-28

·

CVE-2015-6488

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Allen-Bradley MicroLogix 1100 versions before B FRN 15.000 Allen-Bradley MicroLogix 1400 versions before B FRN 15.003
Description The issue is related to a cross-site scripting (XSS) vulnerability in the web server of the affected devices. This vulnerability exists due to the lack of protection for the web page structure, allowing remote attackers to inject arbitrary web script or HTML via unspecified vectors. Exploitation of this vulnerability may enable an attacker to execute arbitrary code when a user navigates to a specially crafted link.
Recommendations For Allen-Bradley MicroLogix 1100 versions before B FRN 15.000, update to version B FRN 15.000 or later. For Allen-Bradley MicroLogix 1400 versions before B FRN 15.003, update to version B FRN 15.003 or later.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-11950
BDU:2016-01725
CVE-2015-6488

Produtos afetados

Allen-Bradley Micrologix 1100
Allen-Bradley Micrologix 1400