VYPR
Unrated severityNVD Advisory· Published Oct 18, 2015· Updated May 6, 2026

CVE-2015-6477

CVE-2015-6477

Description

Multiple cross-site scripting (XSS) vulnerabilities in the Wind Farm Portal application in Nordex Control 2 (NC2) SCADA 16 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple cross-site scripting vulnerabilities in Nordex Control 2 SCADA V16 and earlier allow remote attackers to inject arbitrary web script via the login username parameter.

Vulnerability

The Wind Farm Portal application in Nordex Control 2 (NC2) SCADA V16 and prior versions contains multiple cross-site scripting (XSS) vulnerabilities [1]. The vulnerable parameter is the username field in the login form [2]. The application fails to properly neutralize user input before returning it in web pages, allowing injection of arbitrary HTML and JavaScript.

Exploitation

An attacker can exploit this vulnerability remotely without authentication by sending a crafted POST request to the /login endpoint with a malicious payload in the userName parameter [2]. No special network position or user interaction is required beyond the victim accessing the affected page. The proof-of-concept demonstrates injecting a script that triggers an alert box [2].

Impact

Successful exploitation allows the attacker to execute arbitrary HTML and script content in the context of the victim's browser session [1]. This can lead to session hijacking, redirection to malicious sites, network reconnaissance, and planting of backdoor programs [1]. The attacker gains the ability to manipulate the client-server session and potentially access control system networks.

Mitigation

Nordex has produced an update to mitigate this vulnerability, but the specific fixed version is not disclosed in the available references [1]. Users should contact Nordex for the patch. No workarounds are mentioned. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 23, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.