VulnerabilityModified
CVE-2018-7795
A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product.
MEDIUM 5.4EPSS 2.32%
Does this matter?
Lower severity and a low EPSS score (2.32%). Track it; it rarely justifies an emergency change on its own.
Description
A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product. The vulnerability makes the product susceptible to cross site scripting attack on its web browser. User inputs can be manipulated to cause execution of java script code.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
- EPSS
- 2.32% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- schneider-electric/powerlogic pm5560 firmware
- Source
- cybersecurity@se.com
References
- http://www.securityfocus.com/bid/105170Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-240-03Mitigation, Third Party Advisory, US Government Resource
- https://www.schneider-electric.com/en/download/document/SEVD-2018-228-01/Mitigation, Vendor Advisory
- http://www.securityfocus.com/bid/105170Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-240-03Mitigation, Third Party Advisory, US Government Resource
- https://www.schneider-electric.com/en/download/document/SEVD-2018-228-01/Mitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.