Reflected Cross-Site Scripting Vulnerability in Schneider Electric Modicon Products
CVE-2015-6462
5.4MEDIUM
What is CVE-2015-6462?
This vulnerability allows an attacker to exploit reflected cross-site scripting in Schneider Electric Modicon PLC products. By crafting a specific URL that contains malicious JavaScript, an attacker can cause the code to be executed in the browser of users accessing the affected PLCs. This could lead to unauthorized actions performed on behalf of the user, compromising the security of the affected systems.
Affected Version(s)
Schneider Electric Modicon PLC BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, and BMXP342030H.