Lucene search

K
cveSchneiderCVE-2019-6853
HistoryNov 20, 2019 - 10:15 p.m.

CVE-2019-6853

2019-11-2022:15:12
CWE-79
schneider
web.nvd.nist.gov
63
cwe-79
vulnerability
andover continuum
cross-site scripting
xss
nvd
cve-2019-6853

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6

Confidence

High

EPSS

0.001

Percentile

33.8%

A CWE-79: Failure to Preserve Web Page Structure vulnerability exists in Andover Continuum (models 9680, 5740 and 5720, bCX4040, bCX9640, 9900, 9940, 9924 and 9702) , which could enable a successful Cross-site Scripting (XSS attack) when using the products web server.

Affected configurations

Nvd
Node
schneider-electricandover_continuum_9680_firmwareMatch-
AND
schneider-electricandover_continuum_9680Match-
Node
schneider-electricandover_continuum_5740_firmwareMatch-
AND
schneider-electricandover_continuum_5740Match-
Node
schneider-electricandover_continuum_5720_firmwareMatch-
AND
schneider-electricandover_continuum_5720Match-
Node
schneider-electricandover_continuum_bcx4040_firmwareMatch-
AND
schneider-electricandover_continuum_bcx4040Match-
Node
schneider-electricandover_continuum_bcx9640_firmwareMatch-
AND
schneider-electricandover_continuum_bcx9640Match-
Node
schneider-electricandover_continuum_9900_firmwareMatch-
AND
schneider-electricandover_continuum_9900Match-
Node
schneider-electricandover_continuum_9940_firmwareMatch-
AND
schneider-electricandover_continuum_9940Match-
Node
schneider-electricandover_continuum_9941_firmwareMatch-
AND
schneider-electricandover_continuum_9941Match-
Node
schneider-electricandover_continuum_9924_firmwareMatch-
AND
schneider-electricandover_continuum_9924Match-
Node
schneider-electricandover_continuum_9702_firmwareMatch-
AND
schneider-electricandover_continuum_9702Match-
Node
schneider-electricandover_continuum_9200_firmwareMatch-
AND
schneider-electricandover_continuum_9200Match-
VendorProductVersionCPE
schneider-electricandover_continuum_9680_firmware-cpe:2.3:o:schneider-electric:andover_continuum_9680_firmware:-:*:*:*:*:*:*:*
schneider-electricandover_continuum_9680-cpe:2.3:h:schneider-electric:andover_continuum_9680:-:*:*:*:*:*:*:*
schneider-electricandover_continuum_5740_firmware-cpe:2.3:o:schneider-electric:andover_continuum_5740_firmware:-:*:*:*:*:*:*:*
schneider-electricandover_continuum_5740-cpe:2.3:h:schneider-electric:andover_continuum_5740:-:*:*:*:*:*:*:*
schneider-electricandover_continuum_5720_firmware-cpe:2.3:o:schneider-electric:andover_continuum_5720_firmware:-:*:*:*:*:*:*:*
schneider-electricandover_continuum_5720-cpe:2.3:h:schneider-electric:andover_continuum_5720:-:*:*:*:*:*:*:*
schneider-electricandover_continuum_bcx4040_firmware-cpe:2.3:o:schneider-electric:andover_continuum_bcx4040_firmware:-:*:*:*:*:*:*:*
schneider-electricandover_continuum_bcx4040-cpe:2.3:h:schneider-electric:andover_continuum_bcx4040:-:*:*:*:*:*:*:*
schneider-electricandover_continuum_bcx9640_firmware-cpe:2.3:o:schneider-electric:andover_continuum_bcx9640_firmware:-:*:*:*:*:*:*:*
schneider-electricandover_continuum_bcx9640-cpe:2.3:h:schneider-electric:andover_continuum_bcx9640:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 221

CNA Affected

[
  {
    "product": "Andover Continuum models 9680, 5740 and 5720, bCX4040, bCX9640, 9900, 9940, 9924 and 9702",
    "vendor": "Schneider Electric",
    "versions": [
      {
        "status": "affected",
        "version": "Andover Continuum models 9680"
      },
      {
        "status": "affected",
        "version": "5740 and 5720"
      },
      {
        "status": "affected",
        "version": "bCX4040"
      },
      {
        "status": "affected",
        "version": "bCX9640"
      },
      {
        "status": "affected",
        "version": "9900"
      },
      {
        "status": "affected",
        "version": "9940"
      },
      {
        "status": "affected",
        "version": "9924 and 9702"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6

Confidence

High

EPSS

0.001

Percentile

33.8%

Related for CVE-2019-6853