CVE-2020-7482

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
23/03/2020
Last modified:
24/03/2020

Description

A CWE-79:Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists Andover Continuum (All versions), which could cause a Reflective Cross-site Scripting (XSS attack) when using the products' web server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:schneider-electric:andover_continuum_9680_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:andover_continuum_9680:-:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:andover_continuum_5740_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:andover_continuum_5740:-:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:andover_continuum_5720_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:andover_continuum_5720:-:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:andover_continuum_bcx4040_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:andover_continuum_bcx4040:-:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:andover_continuum_bcx9640_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:andover_continuum_bcx9640:-:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:andover_continuum_9900_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:andover_continuum_9900:-:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:andover_continuum_9940_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:andover_continuum_9940:-:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:andover_continuum_9941_firmware:*:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools