« Volver al listado

CVE-2024-8401

Estado: AplazadaMedia (5.4)—

CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability exists when an authenticated attacker modifies folder names within the context of the product.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-8401",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-8401",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-01-28T18:58:00.309671Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cybersecurity@se.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "cybersecurity@se.com",
      "affectedData": [
        {
          "vendor": "Schneider Electric",
          "product": "EcoStruxure Power Monitoring Expert (PME) 2021",
          "versions": [
            {
              "status": "affected",
              "version": "2021 CU1 and prior"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "EcoStruxure Power Monitoring Expert (PME) 2020",
          "versions": [
            {
              "status": "affected",
              "version": "2020 CU3 and prior"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "EcoStruxure Power Operation (EPO) 2022",
          "versions": [
            {
              "status": "affected",
              "version": "CU4 and prior"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "EcoStruxure Power Operation (EPO) 2022 – Advanced Reporting and Dashboards Module",
          "versions": [
            {
              "status": "affected",
              "version": "CU4 and prior"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "EcoStruxure Power Operation (EPO) 2021",
          "versions": [
            {
              "status": "affected",
              "version": "CU4 and prior"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "EcoStruxure Power Operation (EPO) 2021 – Advanced Reporting and Dashboards Module",
          "versions": [
            {
              "status": "affected",
              "version": "CU3 with Hotfix 2 and prior"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "Schneider Electric",
          "product": "EcoStruxure Power SCADA Operation 2020 (PSO) - Advanced Reporting and Dashboards Module",
          "versions": [
            {
              "status": "affected",
              "version": "All Versions"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-01-28T17:15:25.467",
  "references": [
    {
      "url": "https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2024-254-02&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2024-254-02.pdf",
      "source": "cybersecurity@se.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cybersecurity@se.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)\nvulnerability exists when an authenticated attacker modifies folder names within the context of\nthe product."
    },
    {
      "lang": "es",
      "value": "CWE-79: Existe una vulnerabilidad de neutralización inadecuada de la entrada durante la generación de páginas web (‘Cross-site Scripting’) cuando un atacante autenticado modifica los nombres de las carpetas dentro del contexto del producto."
    }
  ],
  "lastModified": "2026-06-17T08:22:30.783",
  "sourceIdentifier": "cybersecurity@se.com"
}