Nordex NC2 Cross-site Scripting
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 1.7%
exploitation probability
1.7%top 24% of all CVEs
observed exploitation
nono source reports it
Cross-site scripting (XSS) vulnerability in the login script in the Wind Farm Portal on Nordex Control 2 (NC2) SCADA devices 15 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected products
Nordex · Nordex Control 2 (NC2) SCADA