Vulnerability Description
PSI GridConnect GmbH Telecontrol Gateway and Smart Telecontrol Unit family, IEC104 Security Proxy versions Telecontrol Gateway 3G Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior, and Telecontrol Gateway XS-MU Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior, and Telecontrol Gateway VM Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior, and Smart Telecontrol Unit TCG Versions 5.0.27, 5.1.19, 6.0.16 and prior, and IEC104 Security Proxy Version 2.2.10 and prior The web application browser interprets input as active HTML, JavaScript, or VBScript, which could allow an attacker to execute arbitrary code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Psigridconnect | Telecontrol Gateway Xs-Mu Firmware | < 5.1.20 |
| Psigridconnect | Telecontrol Gateway Xs-Mu | - |
| Psigridconnect | Telecontrol Gateway Vm Firmware | < 5.1.20 |
| Psigridconnect | Telecontrol Gateway Vm | - |
| Psigridconnect | Telecontrol Gateway 3G Firmware | < 5.1.20 |
| Psigridconnect | Telecontrol Gateway 3G | - |
| Psigridconnect | Smart Telecontrol Unit Tcg Firmware | < 5.1.20 |
| Psigridconnect | Smart Telecontrol Unit Tcg | - |
| Psigridconnect | Iec104 Security Proxy Firmware | <= 2.2.10 |
| Psigridconnect | Iec104 Security Proxy | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/107201Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-19-059-01Third Party AdvisoryUS Government Resource
- http://www.securityfocus.com/bid/107201Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-19-059-01Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2019-6528?
CVE-2019-6528 is a vulnerability with a CVSS score of 8.8 (HIGH). PSI GridConnect GmbH Telecontrol Gateway and Smart Telecontrol Unit family, IEC104 Security Proxy versions Telecontrol Gateway 3G Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior, and Telecontrol Gat...
How severe is CVE-2019-6528?
CVE-2019-6528 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6528?
Check the references section above for vendor advisories and patch information. Affected products include: Psigridconnect Telecontrol Gateway Xs-Mu Firmware, Psigridconnect Telecontrol Gateway Xs-Mu, Psigridconnect Telecontrol Gateway Vm Firmware, Psigridconnect Telecontrol Gateway Vm, Psigridconnect Telecontrol Gateway 3G Firmware.