Description
Cross-site scripting (XSS) vulnerability in the login script in the Wind Farm Portal on Nordex Control 2 (NC2) SCADA devices 15 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.
Published: 2014-11-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Nordex will release a patch for all affected NC2-SCADA versions until the end of 2014. The patching of the NC2-SCADA system has to be done by Nordex. Nordex will upgrade all wind farms with a valid service contract to the patched version of the NC2-SCADA in coordination with normal maintenance operations. Owners of Nordex NC2-based wind farms without a valid service contract can order the patch from Nordex by contacting their local Nordex service organization.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2014-5296 Cross-site scripting (XSS) vulnerability in the login script in the Wind Farm Portal on Nordex Control 2 (NC2) SCADA devices 15 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.
History

Mon, 03 Nov 2025 19:00:00 +0000

Type Values Removed Values Added
Title Nordex NC2 Cross-site Scripting
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:N/AC:M/Au:N/C:N/I:P/A:N'}

cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P'}


Subscriptions

Nordex Nordex Control 2 Scada
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-11-03T18:50:14.150Z

Reserved: 2014-08-22T00:00:00.000Z

Link: CVE-2014-5408

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-11-05T11:55:06.437

Modified: 2025-11-03T19:15:38.847

Link: CVE-2014-5408

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses