CVE-2015-6462

Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC client browser.
References
Link Resource
https://ics-cert.us-cert.gov/advisories/ICSA-15-246-02 US Government Resource Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:schneider-electric:bmxnoc0401_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxnoc0401:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:schneider-electric:bmxnoe0100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxnoe0100:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:schneider-electric:bmxnoe0110_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxnoe0110:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:schneider-electric:bmxnoe0110h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxnoe0110h:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:schneider-electric:bmxnor0200h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxnor0200h:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:schneider-electric:bmxp342020_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxp342020:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:schneider-electric:bmxp342020h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxp342020h:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:schneider-electric:bmxp342030_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxp342030:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:schneider-electric:bmxp3420302_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxp3420302:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:schneider-electric:bmxp3420302h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxp3420302h:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:schneider-electric:bmxp342030h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:bmxp342030h:-:*:*:*:*:*:*:*

Information

Published : 2019-03-21 12:29

Updated : 2019-10-09 16:14


NVD link : CVE-2015-6462

Mitre link : CVE-2015-6462


JSON object : View

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Advertisement

dedicated server usa

Products Affected

schneider-electric

  • bmxnor0200h_firmware
  • bmxnoe0110h
  • bmxp342020h
  • bmxp342030h_firmware
  • bmxp342030
  • bmxnoe0100
  • bmxp342030_firmware
  • bmxnoc0401_firmware
  • bmxnoe0110h_firmware
  • bmxnor0200h
  • bmxp342030h
  • bmxp3420302h
  • bmxnoe0110_firmware
  • bmxnoe0100_firmware
  • bmxp342020
  • bmxp3420302h_firmware
  • bmxp342020h_firmware
  • bmxnoe0110
  • bmxp342020_firmware
  • bmxnoc0401
  • bmxp3420302_firmware
  • bmxp3420302