CVE-2023-5986
Published: Nov 15, 2023
Modified: Dec 2, 2024
CVSS v3.1
8.2
Description
A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed.
| Vendor | Product | Versions |
|---|---|---|
Schneider Electric | EcoStruxure Power Monitoring Expert (PME) | affected Version 2020 CU2 and prioraffected Version 2021 CU1 and prior |
Schneider Electric | EcoStruxure Power Operation (EPO) – Advanced Reporting and Dashboards Module | affected Advanced Reporting and Dashboards Module 2021 prior to CU2 for EcoStruxure Power Operation 2021affected Advanced Reporting and Dashboards Module 2020 prior to CU3 |
Schneider Electric | EcoStruxure Power SCADA Operation (PSO) - Advanced Reporting and Dashboards Module | affected EcoStruxure Power SCADA Operation (PSO) 2020 or 2020 R2 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now