PT-2018-2178 · Schneider Electric · Ecostruxure Power Monitoring Expert+2

Publicado

2018-12-13

·

Atualizado

2019-02-11

·

CVE-2018-7797

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions EcoStruxure Power Monitoring Expert (PME) versions 8.2 through 9.0 EcoStruxure Energy Expert versions 1.3 through 2.0 EcoStruxure Power SCADA Operation (PSO) versions 8.2 through 9.0 Advanced Reports and Dashboards Module
Description A URL redirection issue exists that could lead to a phishing attack when users are redirected to a malicious site. The vulnerability is related to insufficient protection of web pages, which could allow a remote attacker to redirect users to an arbitrary URL.
Recommendations For EcoStruxure Power Monitoring Expert (PME) versions 8.2 through 9.0, update to a version that includes the fix for this issue. For EcoStruxure Energy Expert versions 1.3 through 2.0, update to a version that includes the fix for this issue. For EcoStruxure Power SCADA Operation (PSO) versions 8.2 through 9.0 Advanced Reports and Dashboards Module, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the affected web pages to minimize the risk of exploitation.

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-00131
CVE-2018-7797

Produtos afetados

Ecostruxure Energy Expert
Ecostruxure Power Monitoring Expert
Ecostruxure Powerscada Operation