6.1
CVE-2018-7797
- EPSS 0.76%
- Veröffentlicht 17.12.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:12:45
- Erkennungen
A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module, EcoStruxure Power Monitoring Expert (PME) v9.0, EcoStruxure Energy Expert v2.0, and EcoStruxure Power SCADA Operation (PSO) 9.0 Advanced Reports and Dashboards Module which could cause a phishing attack when redirected to a malicious site.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electric ≫ Ecostruxure Energy Expert Version 1.3
Schneider-electric ≫ Ecostruxure Energy Expert Version 2.0
Schneider-electric ≫ Ecostruxure Power Monitoring Expert Version 8.2
Schneider-electric ≫ Ecostruxure Power Monitoring Expert Version 9.0
Schneider-electric ≫ Ecostruxure Power Scada Operation Version 8.2
Schneider-electric ≫ Ecostruxure Power Scada Operation Version 9.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.76% | 0.502 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.1 | 2.8 | 2.7 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
|
| NIST | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
http://www.securityfocus.com/bid/106277
https://www.schneider-electric.com/en/download/document/SEVD-2018-347-01/