CVE-2014-5411

Severity
3.5LOW
EPSS
0.5%
top 34.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 18
Latest updateMay 14

Description

Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

CVSS vector

AV:N/AC:H/C:N/I:N/A:CExploitability: 3.9 | Impact: 6.9

Affected Packages4 packages

CVEListV5schneider_electric/clearscada2010 R3 (build 72.4560), 2010 R3.1 (build 72.4644)+1
NVDaveva/clearscada2010, 2013+1

🔴Vulnerability Details

2
GHSA
GHSA-36cr-x5x9-99f3: Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allow remote au2022-05-14
CVEList
Schneider Electric SCADA Expert ClearSCADA Cross-site Scripting2014-09-18
CVE-2014-5411 (LOW CVSS 3.5) | Multiple cross-site scripting (XSS) | cvebase.io