HTML/JavaScript Injection Vulnerability in Pluto Safety PLC Gateway Devices by ABB
CVE-2018-18997

6.1MEDIUM

Key Information:

Vendor

Abb

Vendor
CVE Published:
3 January 2019

What is CVE-2018-18997?

An HTML/JavaScript injection vulnerability exists in the Pluto Safety PLC Gateway Ethernet devices manufactured by ABB. This flaw allows an unauthenticated attacker to exploit the administrative web interface and inject malicious HTML or JavaScript code into device properties. Such exploitation could lead to the execution or display of the injected payload in the browsers of visitors interacting with the compromised devices, posing a significant security risk.

Affected Version(s)

ABB GATE-E1 and GATE-E2 All versions

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.