PT-2019-7202 · Schneider Electric · Modicon Bmxnoe0110 +6

Aditya K. Sood

+1

·

Published

2019-03-21

·

Updated

2024-04-10

·

CVE-2015-6462

CVSS v2.0
3.5
VectorAV:N/AC:M/Au:S/C:N/I:P/A:N

Name of the Vulnerable Software and Affected Versions:

Schneider Electric Modicon BMXNOC0401

Schneider Electric Modicon BMXNOE0100

Schneider Electric Modicon BMXNOE0110

Schneider Electric Modicon BMXNOE0110H

Schneider Electric Modicon BMXNOR0200H

Schneider Electric Modicon BMXP342020

Schneider Electric Modicon BMXP342020H

Schneider Electric Modicon BMXP342030

Schneider Electric Modicon BMXP3420302

Schneider Electric Modicon BMXP3420302H

Schneider Electric Modicon BMXP342030H

Description:

The issue allows an attacker to craft a specific URL that contains JavaScript, which will be executed on the client browser of the PLC. This is a Reflected Cross-Site Scripting (nonpersistent) issue.

Recommendations:

For each of the affected devices, apply the recommended patch or update from Schneider Electric to resolve the issue.

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2015-6462

Affected Products

Modicon Bmxnoc0401
Modicon Bmxnoe0100
Modicon Bmxnoe0110
Modicon Bmxnor0200
Modicon Bmxp342020
Modicon Bmxp342030
Modicon Bmxp3420302