Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-5411


Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.


Published

2014-09-18T10:55:11.640

Last Modified

2025-11-04T23:15:33.223

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:H/Au:S/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: HIGH
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

6.9

Weaknesses
  • Type: Secondary
    CWE-79
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application aveva clearscada 2010 Yes
Application aveva clearscada 2010 Yes
Application aveva clearscada 2013 Yes
Application aveva clearscada 2013 Yes
Application aveva clearscada 2013 Yes
Application aveva clearscada 2013 Yes
Application aveva clearscada 2013 Yes
Application schneider-electric scada_expert_clearscada 2013 Yes
Application schneider-electric scada_expert_clearscada 2014 Yes

References