← back
CVE-2014-5408

Nordex NC2 Cross-site Scripting

CVSS 7.5 EPSS 1.7%CWE-79
Cross-site scripting (XSS) vulnerability in the login script in the Wind Farm Portal on Nordex Control 2 (NC2) SCADA devices 15 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.
AV:N/AC:L/Au:N/C:P/I:P/A:P

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →