Cross-Site Scripting Vulnerability in Schneider Electric Products
CVE-2024-8401

5.4MEDIUM

Summary

A cross-site scripting vulnerability exists in Schneider Electric products, which allows authenticated attackers to manipulate folder names. This can lead to the injection of malicious scripts, enabling attackers to execute harmful code in the context of a user's session. Users should ensure they are using the latest software versions and follow security best practices to mitigate potential risks.

Affected Version(s)

EcoStruxure Power Monitoring Expert (PME) 2020 2020 CU3 and prior

EcoStruxure Power Monitoring Expert (PME) 2021 2021 CU1 and prior

EcoStruxure Power Operation (EPO) 2021 CU4 and prior

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.