QID 590490

Date Published: 2021-10-14

QID 590490: Schneider Electric PowerLogic PM8ECC Cross-Site Scripting (XSS) Vulnerability Vulnerability (ICSA-16-173-02)

AFFECTED PRODUCTS
Schneider Electric reports that the vulnerability affects the following versions of PowerLogic PM8ECC:
PowerLogic PM8ECC, firmware versions prior to Version 2.651

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could allow an unauthenticated attacker to inject arbitrary JavaScript in a specially crafted URL request where the response containing user data is returned to the web browser without being made safe to display.

  • CVSS V3 rated as High - 6.1 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-16-173-02 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590490

    Software Advisories
    Advisory ID Software Component Link
    ICSA-16-173-02 URL Logo www.us-cert.gov/ics/advisories/ICSA-16-173-02