CVE-2015-6462: XSS
Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC client browser.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6462?
The severity of CVE-2015-6462 is medium with a severity value of 5.4.
How does Reflected Cross-Site Scripting (nonpersistent) work?
Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL containing JavaScript that will be executed on vulnerable Schneider Electric Modicon devices.
Which Schneider Electric Modicon devices are affected by CVE-2015-6462?
The Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H devices are affected by CVE-2015-6462.
How can I fix CVE-2015-6462?
To fix CVE-2015-6462, it is recommended to apply the latest firmware updates provided by Schneider Electric.
Where can I find more information about CVE-2015-6462?
More information about CVE-2015-6462 can be found at the following reference: https://ics-cert.us-cert.gov/advisories/ICSA-15-246-02