PT-2025-34590 · Scada-Lts · Scada-Lts

Nmmorette

·

Published

2025-08-24

·

Updated

2025-08-25

·

CVE-2025-9404

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Scada-LTS versions prior to 2.7.8.2
Description: A vulnerability was identified in Scada-LTS up to version 2.7.8.1. The affected element is an unknown function within the /pointHierarchySLTS file of the Folder Handler component. Manipulation of the Title argument leads to cross-site scripting. The attack can be initiated remotely, and the exploit is publicly available.
Recommendations: Scada-LTS versions prior to 2.7.8.2: Update to version 2.7.8.2 or later to resolve this issue. As a temporary workaround, consider restricting access to the /pointHierarchySLTS file or disabling the vulnerable function until a patch is available.

Exploit

Fix

Code Injection

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-14904
CVE-2025-9404

Affected Products

Scada-Lts