CVE-2018-7797
Summary
| CVE | CVE-2018-7797 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-12-17 22:29:00 UTC |
| Updated | 2019-02-11 20:11:00 UTC |
| Description | A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module, EcoStruxure Power Monitoring Expert (PME) v9.0, EcoStruxure Energy Expert v2.0, and EcoStruxure Power SCADA Operation (PSO) 9.0 Advanced Reports and Dashboards Module which could cause a phishing attack when redirected to a malicious site. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Multiple Schneider Electric EcoStruxure Products CVE-2018-7797 Open Redirection Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| www.schneider-electric.com/en/download/document/SEVD-2018-347-01 |
CONFIRM |
www.schneider-electric.com |
Vendor Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590912 Schneider Electric EcoStruxure Open Redirect Vulnerability (ICSA-18-354-02)