Multiple vulnerabilities have been reported in Schneider Electric products which could allow an attacker to bypass security controls, access sensitive information through the victim¿s browser, perform cross-site scripting (XSS) attacks, execute arbitrary commands, and potentially compromise the targeted system.
Target Audience:
All organizations and individuals using the affected Schneider Electric products.
Risk Assessment:
Medium risk of cross-site scripting (XSS) in user browsers and OS command execution during authenticated SSH sessions on Saitel devices.
Impact Assessment:
Potential exposure or modification of data rendered in a victim's browser, and possible execution of unauthorised OS commands on Saitel devices, depending on the privileges of the account used.
The information provided herein is on "as is" basis, without warranty of any kind.