3.5
CVSSv2

CVE-2015-6462

Published: 21/03/2019 Updated: 10/04/2024
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 312
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Reflected Cross-Site Scripting (nonpersistent) allows an malicious user to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC client browser.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric bmxnoc0401_firmware -

schneider-electric bmxnoe0100_firmware -

schneider-electric bmxnoe0110_firmware -

schneider-electric bmxnoe0110h_firmware -

schneider-electric bmxnor0200h_firmware -

schneider-electric modicon_m340_bmxp342020_firmware -

schneider-electric modicon_m340_bmxp342020h_firmware -

schneider-electric modicon_m340_bmxp342030_firmware -

schneider-electric modicon_m340_bmxp3420302_firmware -

schneider-electric modicon_m340_bmxp3420302h_firmware -

schneider-electric modicon_m340_bmxp342030h_firmware -