CVE-2018-7795
Summary
| CVE | CVE-2018-7795 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-29 20:29:00 UTC |
| Updated | 2018-11-07 19:09:00 UTC |
| Description | A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product. The vulnerability makes the product susceptible to cross site scripting attack on its web browser. User inputs can be manipulated to cause execution of java script code. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Security Notification – PowerLogic PM5560 | Schneider Electric |
CONFIRM |
www.schneider-electric.com |
Mitigation, Vendor Advisory |
| Schneider Electric PowerLogic PM5560 CVE-2018-7795 Unspecified Cross Site Scripting Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| Schneider Electric PowerLogic PM5560 | ICS-CERT |
MISC |
ics-cert.us-cert.gov |
Mitigation, Third Party Advisory, US Government Resource |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590482 Schneider Electric PowerLogic PM5560 Cross Protocol Injection Vulnerability(ICSA-18-240-03)