SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-7795

A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product.

MEDIUM 5.4EPSS 2.32%

Does this matter?

Lower severity and a low EPSS score (2.32%). Track it; it rarely justifies an emergency change on its own.

Description

A Cross Protocol Injection vulnerability exists in Schneider Electric's PowerLogic (PM5560 prior to FW version 2.5.4) product. The vulnerability makes the product susceptible to cross site scripting attack on its web browser. User inputs can be manipulated to cause execution of java script code.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
EPSS
2.32% probability · 83th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
schneider-electric/powerlogic pm5560 firmware
Source
cybersecurity@se.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.