Remote file inclusion allows an attacker to craft a specific URL referencing the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC web server, which, when launched, will result in the browser redirecting to a remote file via a Java script loaded with the web page.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-15-246-02 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: icscert
Published: 2019-03-21T18:17:48
Updated: 2024-08-06T07:22:21.501Z
Reserved: 2015-08-17T00:00:00
Link: CVE-2015-6461
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-03-21T19:29:00.267
Modified: 2024-11-21T02:35:00.673
Link: CVE-2015-6461
Redhat
No data.