CVE-2018-7797 Information

Description

A URL redirection vulnerability exists in Power Monitoring Expert Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions) EcoStruxure Energy Expert 1.3 (formerly Power Manager) EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module EcoStruxure Power Monitoring Expert (PME) v9.0 EcoStruxure Energy Expert v2.0 and EcoStruxure Power SCADA Operation (PSO) 9.0 Advanced Reports and Dashboards Module which could cause a phishing attack when redirected to a malicious site.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

http://www.securityfocus.com/bid/106277 https://www.schneider-electric.com/en/download/document/SEVD-2018-347-01/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: