First published: Sun Jun 26 2016(Updated: )
Cross-site scripting (XSS) vulnerability in the Schneider Electric PowerLogic PM8ECC module before 2.651 for PowerMeter 800 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Powerlogic Pm8ecc Firmware | <=2.60 | |
Schneider-electric Powerlogic Pm8ecc |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4513 is classified as a medium severity cross-site scripting (XSS) vulnerability.
To mitigate CVE-2016-4513, upgrade the Schneider Electric PowerLogic PM8ECC module firmware to version 2.651 or later.
CVE-2016-4513 affects Schneider Electric PowerLogic PM8ECC modules with firmware versions prior to 2.651.
Yes, CVE-2016-4513 could potentially allow remote attackers to inject malicious web scripts, leading to unauthorized access.
CVE-2016-4513 is a remote vulnerability that can be exploited by attackers over the network.