Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC web server, which, when launched, will result in the browser redirecting to a remote file via a Java script loaded with the web page.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Schneider-electric
Subscribe
|
Bmxnoc0401
Subscribe
Bmxnoc0401 Firmware
Subscribe
Bmxnoe0100
Subscribe
Bmxnoe0100 Firmware
Subscribe
Bmxnoe0110
Subscribe
Bmxnoe0110 Firmware
Subscribe
Bmxnoe0110h
Subscribe
Bmxnoe0110h Firmware
Subscribe
Bmxnor0200h
Subscribe
Bmxnor0200h Firmware
Subscribe
Modicon M340 Bmxp342020
Subscribe
Modicon M340 Bmxp342020 Firmware
Subscribe
Modicon M340 Bmxp342020h
Subscribe
Modicon M340 Bmxp342020h Firmware
Subscribe
Modicon M340 Bmxp342030
Subscribe
Modicon M340 Bmxp3420302
Subscribe
Modicon M340 Bmxp3420302 Firmware
Subscribe
Modicon M340 Bmxp3420302h
Subscribe
Modicon M340 Bmxp3420302h Firmware
Subscribe
Modicon M340 Bmxp342030 Firmware
Subscribe
Modicon M340 Bmxp342030h
Subscribe
Modicon M340 Bmxp342030h Firmware
Subscribe
|
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://ics-cert.us-cert.gov/advisories/ICSA-15-246-02 |
|
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-06T07:22:21.501Z
Reserved: 2015-08-17T00:00:00
Link: CVE-2015-6461
No data.
Status : Modified
Published: 2019-03-21T19:29:00.267
Modified: 2024-11-21T02:35:00.673
Link: CVE-2015-6461
No data.
OpenCVE Enrichment
No data.