5.4
CVSSv3

CVE-2015-6461

Published: 21/03/2019 Updated: 10/04/2024
CVSS v2 Base Score: 5.5 | Impact Score: 4.9 | Exploitability Score: 8
CVSS v3 Base Score: 5.4 | Impact Score: 2.5 | Exploitability Score: 2.8
VMScore: 490
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N

Vulnerability Summary

Remote file inclusion allows an malicious user to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC web server, which, when launched, will result in the browser redirecting to a remote file via a Java script loaded with the web page.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric bmxnoc0401_firmware -

schneider-electric bmxnoe0100_firmware -

schneider-electric bmxnoe0110_firmware -

schneider-electric bmxnoe0110h_firmware -

schneider-electric bmxnor0200h_firmware -

schneider-electric modicon_m340_bmxp342020_firmware -

schneider-electric modicon_m340_bmxp342020h_firmware -

schneider-electric modicon_m340_bmxp342030_firmware -

schneider-electric modicon_m340_bmxp3420302_firmware -

schneider-electric modicon_m340_bmxp3420302h_firmware -

schneider-electric modicon_m340_bmxp342030h_firmware -