CVE-2015-6461
Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC…
Does this matter?
Lower severity and a low EPSS score (0.87%). Track it; it rarely justifies an emergency change on its own.
Description
Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC web server, which, when launched, will result in the browser redirecting to a remote file via a Java script loaded with the web page.
- CVSS 3.0
- 5.4 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.87% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-98, CWE-20
- Affected
- schneider-electric/bmxnoc0401 firmware · schneider-electric/bmxnoe0100 firmware · schneider-electric/bmxnoe0110 firmware · schneider-electric/bmxnoe0110h firmware · schneider-electric/bmxnor0200h firmware · schneider-electric/modicon m340 bmxp342020 firmware · schneider-electric/modicon m340 bmxp342020h firmware · schneider-electric/modicon m340 bmxp342030 firmware · schneider-electric/modicon m340 bmxp3420302 firmware · schneider-electric/modicon m340 bmxp3420302h firmware · schneider-electric/modicon m340 bmxp342030h firmware
- Source
- ics-cert@hq.dhs.gov
References
- https://ics-cert.us-cert.gov/advisories/ICSA-15-246-02Third Party Advisory, US Government Resource
- https://ics-cert.us-cert.gov/advisories/ICSA-15-246-02Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.