QID 590921
Date Published: 2022-07-18
QID 590921: Schneider Electric U.motion din rail and touch panel servers Multiple Vulnerabilities (SEVD-2019-253-01)
AFFECTED PRODUCTS
U.motion servers
MEG6501-0001 - U.motion KNX server
MEG6501-0002 - U.motion KNX Server Plus
MEG6260-0410 - U.motion KNX Server Plus, Touch 10
MEG6260-0415 - U.motion KNX Server Plus, Touch 15
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
Cross-Site Scripting (XSS) vulnerability exists, which could allow an attacker to inject client-side script when a user visits a web page. Incorrect Authorization vulnerability exists, which could allow the file system to access the wrong file. Server-Side Request Forgery (SSRF) vulnerability exists, which could cause server configuration data to be exposed when an attacker modifies a URL Incorrect Authorization vulnerability exists, which could allow a user with low privileges to delete a critical file.
Customers are advised to refer to CERT MITIGATIONS section SEVD-2019-253-01 for affected packages and patching details.
- SEVD-2019-253-01 -
www.se.com/ww/en/download/document/SEVD-2019-253-01/
CVEs related to QID 590921
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SEVD-2019-253-01 |
|