MEDIUM · 5.4

CVE-2015-6462

Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BM...

Vulnerability Description

Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC client browser.

CVSS Score

5.4

MEDIUM

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
Schneider-ElectricBmxnoc0401 Firmware-
Schneider-ElectricBmxnoc0401-
Schneider-ElectricBmxnoe0100 Firmware-
Schneider-ElectricBmxnoe0100-
Schneider-ElectricBmxnoe0110 Firmware-
Schneider-ElectricBmxnoe0110-
Schneider-ElectricBmxnoe0110H Firmware-
Schneider-ElectricBmxnoe0110H-
Schneider-ElectricBmxnor0200H Firmware-
Schneider-ElectricBmxnor0200H-
Schneider-ElectricModicon M340 Bmxp342020 Firmware-
Schneider-ElectricModicon M340 Bmxp342020-
Schneider-ElectricModicon M340 Bmxp342020H Firmware-
Schneider-ElectricModicon M340 Bmxp342020H-
Schneider-ElectricModicon M340 Bmxp342030 Firmware-
Schneider-ElectricModicon M340 Bmxp342030-
Schneider-ElectricModicon M340 Bmxp3420302 Firmware-
Schneider-ElectricModicon M340 Bmxp3420302-
Schneider-ElectricModicon M340 Bmxp3420302H Firmware-
Schneider-ElectricModicon M340 Bmxp3420302H-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2015-6462?

CVE-2015-6462 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BM...

How severe is CVE-2015-6462?

CVE-2015-6462 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2015-6462?

Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Bmxnoc0401 Firmware, Schneider-Electric Bmxnoc0401, Schneider-Electric Bmxnoe0100 Firmware, Schneider-Electric Bmxnoe0100, Schneider-Electric Bmxnoe0110 Firmware.