Medium severity5.4NVD Advisory· Published Jul 11, 2024· Updated Jun 17, 2026
CVE-2024-6528
CVE-2024-6528
Description
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a vulnerability leading to a cross-site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload.
Affected products
8- cpe:2.3:o:schneider-electric:modicon_lmc058_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:modicon_m241_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:modicon_m251_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:modicon_m258_firmware:*:*:*:*:*:*:*:*
- cpe:2.3:o:schneider-electric:modicon_m262_firmware:*:*:*:*:*:*:*:*
All versions+ 2 more
- (no CPE)range: All versions
- (no CPE)range: All versions
- (no CPE)range: All Versions
Patches
Vulnerability mechanics
References
1- download.schneider-electric.com/filesnvdVendor Advisory
News mentions
0No linked articles in our index yet.