CVE-2013-2762: CSRF
The Schneider Electric Magelis XBT HMI controller has a default password for authentication of configuration uploads, which makes it easier for remote attackers to bypass intended access restrictions via crafted configuration data.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2762?
CVE-2013-2762 is considered a high severity vulnerability due to the potential for unauthorized access.
How do I fix CVE-2013-2762?
To mitigate CVE-2013-2762, change the default password used for authentication in the Schneider Electric Magelis XBT HMI controller.
What impact does CVE-2013-2762 have on system security?
CVE-2013-2762 allows remote attackers to bypass access restrictions, potentially leading to unauthorized configuration changes.
Which devices are affected by CVE-2013-2762?
CVE-2013-2762 specifically affects the Schneider Electric Magelis XBT HMI controller.
Is there a patch available for CVE-2013-2762?
There is no specific patch for CVE-2013-2762; the recommended mitigation is to change the default password.