PT-2015-2585 · Allen Bradley · Allen-Bradley Micrologix 1400+1

Ilya Karpov

·

Published

2015-10-28

·

Updated

2015-10-28

·

CVE-2015-6488

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Allen-Bradley MicroLogix 1100 versions before B FRN 15.000 Allen-Bradley MicroLogix 1400 versions before B FRN 15.003
Description The issue is related to a cross-site scripting (XSS) vulnerability in the web server of the affected devices. This vulnerability exists due to the lack of protection for the web page structure, allowing remote attackers to inject arbitrary web script or HTML via unspecified vectors. Exploitation of this vulnerability may enable an attacker to execute arbitrary code when a user navigates to a specially crafted link.
Recommendations For Allen-Bradley MicroLogix 1100 versions before B FRN 15.000, update to version B FRN 15.000 or later. For Allen-Bradley MicroLogix 1400 versions before B FRN 15.003, update to version B FRN 15.003 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11950
BDU:2016-01725
CVE-2015-6488

Affected Products

Allen-Bradley Micrologix 1100
Allen-Bradley Micrologix 1400