PT-2025-34590 · Scada-Lts · Scada-Lts
Nmmorette
·
Published
2025-08-24
·
Updated
2025-08-25
·
CVE-2025-9404
CVSS v2.0
5.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Scada-LTS versions prior to 2.7.8.2
Description:
A vulnerability was identified in Scada-LTS up to version 2.7.8.1. The affected element is an unknown function within the
/pointHierarchySLTS file of the Folder Handler component. Manipulation of the Title argument leads to cross-site scripting. The attack can be initiated remotely, and the exploit is publicly available.Recommendations:
Scada-LTS versions prior to 2.7.8.2: Update to version 2.7.8.2 or later to resolve this issue. As a temporary workaround, consider restricting access to the
/pointHierarchySLTS file or disabling the vulnerable function until a patch is available.Exploit
Fix
Code Injection
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Scada-Lts