CVE-2018-18997

Pluto Safety PLC Gateway Ethernet devices in ABB GATE-E1 and GATE-E2 all versions allows an unauthenticated attacker using the administrative web interface to insert an HTML/Javascript payload into any of the device properties, which may allow an attacker to display/execute the payload in a visitor browser.
References
Link Resource
https://ics-cert.us-cert.gov/advisories/ICSA-18-352-01 Mitigation Third Party Advisory
http://www.securityfocus.com/bid/106247 Third Party Advisory VDB Entry
Configurations

Configuration 1


Information

Published : 2019-01-03 10:29

Updated : 2019-10-09 11:37


NVD link : CVE-2018-18997

Mitre link : CVE-2018-18997

Products Affected
No products.
CWE