PT-2015-2585 · Allen Bradley · Allen-Bradley Micrologix 1400+1
Ilya Karpov
·
Publicado
2015-10-28
·
Atualizado
2015-10-28
·
CVE-2015-6488
CVSS v2.0
4.3
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Allen-Bradley MicroLogix 1100 versions before B FRN 15.000
Allen-Bradley MicroLogix 1400 versions before B FRN 15.003
Description
The issue is related to a cross-site scripting (XSS) vulnerability in the web server of the affected devices. This vulnerability exists due to the lack of protection for the web page structure, allowing remote attackers to inject arbitrary web script or HTML via unspecified vectors. Exploitation of this vulnerability may enable an attacker to execute arbitrary code when a user navigates to a specially crafted link.
Recommendations
For Allen-Bradley MicroLogix 1100 versions before B FRN 15.000, update to version B FRN 15.000 or later.
For Allen-Bradley MicroLogix 1400 versions before B FRN 15.003, update to version B FRN 15.003 or later.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Allen-Bradley Micrologix 1100
Allen-Bradley Micrologix 1400