QID 590490
Date Published: 2021-10-14
QID 590490: Schneider Electric PowerLogic PM8ECC Cross-Site Scripting (XSS) Vulnerability Vulnerability (ICSA-16-173-02)
AFFECTED PRODUCTS
Schneider Electric reports that the vulnerability affects the following versions of PowerLogic PM8ECC:
PowerLogic PM8ECC, firmware versions prior to Version 2.651
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
Successful exploitation of this vulnerability could allow an unauthenticated attacker to inject arbitrary JavaScript in a specially crafted URL request where the response containing user data is returned to the web browser without being made safe to display.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-16-173-02 for affected packages and patching details.
Vendor References
- ICSA-16-173-02 -
www.us-cert.gov/ics/advisories/ICSA-16-173-02
CVEs related to QID 590490
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-16-173-02 |
|