CVE-2018-7810: XSS
An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to craft a URL containing JavaScript that will be executed within the user's browser, potentially impacting the machine the browser is running on.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7810?
CVE-2018-7810 has a medium severity, indicating a moderate impact on system security.
How do I fix CVE-2018-7810?
To mitigate CVE-2018-7810, it is essential to apply the latest firmware updates from Schneider Electric for affected devices.
What devices are affected by CVE-2018-7810?
CVE-2018-7810 affects Modicon M340, Premium, Quantum PLCs, and BMXNOR0200 embedded web servers.
What type of vulnerability is CVE-2018-7810?
CVE-2018-7810 is a Cross-site Scripting (XSS) vulnerability that allows the execution of malicious scripts in a user's browser.
Can CVE-2018-7810 be exploited remotely?
Yes, CVE-2018-7810 can be exploited remotely by an attacker crafting a URL containing malicious JavaScript.