IM
IronMonkey Threat Research

CVE-2019-6853 MEDIUM

Published: 2019-11-20 | Last Modified: 2024-11-21 | Status: Modified

Description

A CWE-79: Failure to Preserve Web Page Structure vulnerability exists in Andover Continuum (models 9680, 5740 and 5720, bCX4040, bCX9640, 9900, 9940, 9924 and 9702) , which could enable a successful Cross-site Scripting (XSS attack) when using the products web server.

Additional Descriptions (1)

Una CWE-79: Se presenta una vulnerabilidad de Fallo al Preservar la Estructura de la Página Web en Andover Continuum (modelos 9680, 5740 y 5720, bCX4040, bCX9640, 9900, 9940, 9924 y 9702), lo que podría permitir un ataque de tipo Cross-site Scripting (XSS) cuando se utiliza el servidor web de productos.

CVSS Metrics

Base Score: 6.1 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
ScopeCHANGED
Confidentiality ImpactLOW
Integrity ImpactLOW
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 2.8

Impact Score: 2.7

Base Score: 4.3 (MEDIUM)

AV:N/AC:M/Au:N/C:N/I:P/A:N

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactPARTIAL
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 8.6

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-79
[email protected] Primary
en CWE-79

Affected Products

Vendor Product Version Update Type
schneider-electric andover_continuum_9680_firmware - <built-in method update of dict object at 0x7e60a8b7c700> Operating System
schneider-electric andover_continuum_5740_firmware - <built-in method update of dict object at 0x7e60a8b7f6c0> Operating System
schneider-electric andover_continuum_5720_firmware - <built-in method update of dict object at 0x7e610746ae80> Operating System
schneider-electric andover_continuum_bcx4040_firmware - <built-in method update of dict object at 0x7e60a8b7d080> Operating System
schneider-electric andover_continuum_bcx9640_firmware - <built-in method update of dict object at 0x7e60a8b7d480> Operating System
schneider-electric andover_continuum_9900_firmware - <built-in method update of dict object at 0x7e60a8b7f840> Operating System
schneider-electric andover_continuum_9940_firmware - <built-in method update of dict object at 0x7e6107468e80> Operating System
schneider-electric andover_continuum_9941_firmware - <built-in method update of dict object at 0x7e6107468780> Operating System
schneider-electric andover_continuum_9924_firmware - <built-in method update of dict object at 0x7e61342e4800> Operating System
schneider-electric andover_continuum_9702_firmware - <built-in method update of dict object at 0x7e60a8b7c7c0> Operating System
schneider-electric andover_continuum_9200_firmware - <built-in method update of dict object at 0x7e60eb21a500> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:andover_continuum_9680_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:andover_continuum_9680:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:andover_continuum_5740_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:andover_continuum_5740:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:andover_continuum_5720_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:andover_continuum_5720:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:andover_continuum_bcx4040_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:andover_continuum_bcx4040:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:andover_continuum_bcx9640_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:andover_continuum_bcx9640:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:andover_continuum_9900_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:andover_continuum_9900:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:andover_continuum_9940_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:andover_continuum_9940:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:andover_continuum_9941_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:andover_continuum_9941:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:andover_continuum_9924_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:andover_continuum_9924:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:andover_continuum_9702_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:andover_continuum_9702:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:andover_continuum_9200_firmware:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:andover_continuum_9200:-:*:*:*:*:*:*:*

References

Notification
Message here