CVE-2019-6528 Information
Description
PSI GridConnect GmbH Telecontrol Gateway and Smart Telecontrol Unit family IEC104 Security Proxy versions Telecontrol Gateway 3G Versions 4.2.21 5.0.27 5.1.19 6.0.16 and prior and Telecontrol Gateway XS-MU Versions 4.2.21 5.0.27 5.1.19 6.0.16 and prior and Telecontrol Gateway VM Versions 4.2.21 5.0.27 5.1.19 6.0.16 and prior and Smart Telecontrol Unit TCG Versions 5.0.27 5.1.19 6.0.16 and prior and IEC104 Security Proxy Version 2.2.10 and prior The web application browser interprets input as active HTML JavaScript or VBScript which could allow an attacker to execute arbitrary code.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
http://www.securityfocus.com/bid/107201 https://ics-cert.us-cert.gov/advisories/ICSA-19-059-01
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: