Schneider Electric SCADA Expert ClearSCADA Cross-site Scripting
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-5411
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Aditya Sood
References
More from Schneider Electric
View All →Affected Vendor
Schneider Electric
View all reports →