CVE-2023-5986
Severity
6.1MEDIUM
EPSS
0.2%
top 61.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 15
Description
A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input
attackers can cause the software’s web application to redirect to the chosen domain after a
successful login is performed.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:NExploitability: 2.8 | Impact: 4.7
Affected Packages4 packages
▶CVEListV5schneider_electric/ecostruxure_power_monitoring_expert_(pme)Version 2020 CU2 and prior, Version 2021 CU1 and prior+1
▶CVEListV5schneider_electric/ecostruxure_power_operation_(epo)_–_advanced_reporting_and_dashboards_moduleAdvanced Reporting and Dashboards Module 2020 prior to CU3, Advanced Reporting and Dashboards Module 2021 prior to CU2 for EcoStruxure Power Operation 2021+1
▶CVEListV5schneider_electric/ecostruxure_power_scada_operation_(pso)_-_advanced_reporting_and_dashboards_moduleEcoStruxure Power SCADA Operation (PSO) 2020 or 2020 R2
🔴Vulnerability Details
2CVEList▶
CVE-2023-5986: A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting atta↗2023-11-15
GHSA▶
GHSA-grp5-2x24-q4vj: A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting atta↗2023-11-15