CVE-2023-5987
6.1MEDIUM
Key Information:
Summary
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to a cross site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload.
Affected Version(s)
EcoStruxure Power Monitoring Expert (PME) Version 2020 CU2 and prior
EcoStruxure Power Monitoring Expert (PME) Version 2021 CU1 and prior
EcoStruxure Power Operation (EPO) – Advanced Reporting and Dashboards Module Advanced Reporting and Dashboards Module 2021 prior to CU2 for EcoStruxure Power Operation 2021
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database