CVE-2015-6488: XSS
Cross-site scripting (XSS) vulnerability in the web server on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6488?
CVE-2015-6488 is classified as a medium severity cross-site scripting vulnerability.
How do I fix CVE-2015-6488?
To mitigate CVE-2015-6488, update your Allen-Bradley MicroLogix 1100 devices to firmware version B FRN 15.000 or higher, and MicroLogix 1400 devices to B FRN 15.003 or higher.
What devices are affected by CVE-2015-6488?
CVE-2015-6488 affects Allen-Bradley MicroLogix 1100 devices with firmware before B FRN 15.000 and MicroLogix 1400 devices with firmware before B FRN 15.003.
What kind of attacks can CVE-2015-6488 facilitate?
CVE-2015-6488 can allow remote attackers to inject arbitrary web scripts or HTML into web pages served by the vulnerable devices.
Is there a workaround for CVE-2015-6488?
Currently, the best recommendation is to upgrade the firmware of affected devices to the latest versions to eliminate the vulnerability.