CVE-2015-6462
21.03.2019, 19:29
Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC client browser.
| Vendor | Product | Version |
|---|---|---|
| schneider-electric | bmxnoc0401_firmware | - |
| schneider-electric | bmxnoe0100_firmware | - |
| schneider-electric | bmxnoe0110_firmware | - |
| schneider-electric | bmxnoe0110h_firmware | - |
| schneider-electric | bmxnor0200h_firmware | - |
| schneider-electric | modicon_m340_bmxp342020_firmware | - |
| schneider-electric | modicon_m340_bmxp342020h_firmware | - |
| schneider-electric | modicon_m340_bmxp342030_firmware | - |
| schneider-electric | modicon_m340_bmxp3420302_firmware | - |
| schneider-electric | modicon_m340_bmxp3420302h_firmware | - |
| schneider-electric | modicon_m340_bmxp342030h_firmware | - |
𝑥
= Vulnerable software versions