CVE Database
/

CVE-2024-8401

Back to search

CVE-2024-8401

Published: Jan 28, 2025

Modified: Jan 28, 2025

PUBLISHED

CVSS v3.1

5.4

MEDIUM

Description

CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an authenticated attacker modifies folder names within the context of the product.

VendorProductVersions

Schneider Electric

EcoStruxure Power Monitoring Expert (PME) 2021

affected
2021 CU1 and prior

Schneider Electric

EcoStruxure Power Monitoring Expert (PME) 2020

affected
2020 CU3 and prior

Schneider Electric

EcoStruxure Power Operation (EPO) 2022

affected
CU4 and prior

Schneider Electric

EcoStruxure Power Operation (EPO) 2022 – Advanced Reporting and Dashboards Module

affected
CU4 and prior

Schneider Electric

EcoStruxure Power Operation (EPO) 2021

affected
CU4 and prior

Schneider Electric

EcoStruxure Power Operation (EPO) 2021 – Advanced Reporting and Dashboards Module

affected
CU3 with Hotfix 2 and prior

Schneider Electric

EcoStruxure Power SCADA Operation 2020 (PSO) - Advanced Reporting and Dashboards Module

affected
All Versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

Required

Scope

Changed

Confidentiality

Low

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now