CVE-2015-6461: Input Validation
Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC web server, which, when launched, will result in the browser redirecting to a remote file via a Java script loaded with the web page.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-6461?
CVE-2015-6461 is a vulnerability that allows remote file inclusion on Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC web servers.
How severe is CVE-2015-6461?
CVE-2015-6461 has a severity level of medium (5.4).
How can I exploit CVE-2015-6461?
To exploit CVE-2015-6461, an attacker can craft a specific URL referencing the vulnerable Schneider Electric PLC web server.
What is the potential impact of CVE-2015-6461?
The potential impact of CVE-2015-6461 is that an attacker can gain unauthorized access to sensitive information or perform malicious actions on the affected PLC system.
How can I mitigate CVE-2015-6461?
To mitigate CVE-2015-6461, it is recommended to apply the latest firmware updates provided by Schneider Electric and follow their security guidelines.