CVE-2023-5986: High severity schneider electric ecostruxure power monitoring expert vulnerability
A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-5986?
CVE-2023-5986 is a URL Redirection to Untrusted Site vulnerability that could lead to a cross-site scripting attack.
What is the severity of CVE-2023-5986?
CVE-2023-5986 has a severity rating of 8.2 (high).
Which software is affected by CVE-2023-5986?
Schneider-electric Ecostruxure Power Monitoring Expert 2020, 2020 Cumulative Update 1, 2020 Cumulative Update 2, 2021, and 2021 Cumulative Update 1 are affected by CVE-2023-5986.
How can the CVE-2023-5986 vulnerability be exploited?
Attackers can exploit CVE-2023-5986 by providing a URL-encoded input to cause the software's web application to redirect to an untrusted site, leading to a cross-site scripting attack.
How can I fix CVE-2023-5986?
To fix CVE-2023-5986, apply the necessary security updates provided by Schneider-electric.