PT-2023-6877 · Schneider Electric · Ecostruxure Power Monitoring Expert+2
Published
2023-11-14
·
Updated
2023-11-30
·
CVE-2023-5986
CVSS v2.0
9.4
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
EcoStruxure PowerSCADA Operation (PSO) - Advanced Reporting and Dashboards Module versions (affected versions not specified)
EcoStruxure PowerOperation (EPO) - Advanced Reporting and Dashboards Module versions (affected versions not specified)
EcoStruxure Power Monitoring Expert versions (affected versions not specified)
Description
A URL redirection to untrusted site issue exists, potentially leading to a cross-site scripting attack. By providing a URL-encoded input, attackers can cause the software's web application to redirect to a chosen domain after a successful login. This could allow a remote attacker to redirect a user to an arbitrary URL.
Recommendations
For EcoStruxure PowerSCADA Operation (PSO) - Advanced Reporting and Dashboards Module, consider disabling the URL redirection feature until a patch is available.
For EcoStruxure PowerOperation (EPO) - Advanced Reporting and Dashboards Module, restrict access to the module to minimize the risk of exploitation.
For EcoStruxure Power Monitoring Expert, avoid using URL-encoded inputs in the affected web application until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ecostruxure Power Monitoring Expert
Ecostruxure Poweroperation
Ecostruxure Powerscada Operation