Description
Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC web server, which, when launched, will result in the browser redirecting to a remote file via a Java script loaded with the web page.
Published: 2019-03-21
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

No history.

Subscriptions

Schneider-electric Bmxnoc0401 Bmxnoc0401 Firmware Bmxnoe0100 Bmxnoe0100 Firmware Bmxnoe0110 Bmxnoe0110 Firmware Bmxnoe0110h Bmxnoe0110h Firmware Bmxnor0200h Bmxnor0200h Firmware Modicon M340 Bmxp342020 Modicon M340 Bmxp342020 Firmware Modicon M340 Bmxp342020h Modicon M340 Bmxp342020h Firmware Modicon M340 Bmxp342030 Modicon M340 Bmxp3420302 Modicon M340 Bmxp3420302 Firmware Modicon M340 Bmxp3420302h Modicon M340 Bmxp3420302h Firmware Modicon M340 Bmxp342030 Firmware Modicon M340 Bmxp342030h Modicon M340 Bmxp342030h Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-06T07:22:21.501Z

Reserved: 2015-08-17T00:00:00.000Z

Link: CVE-2015-6461

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-03-21T19:29:00.267

Modified: 2024-11-21T02:35:00.673

Link: CVE-2015-6461

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses