ID

VAR-E-201510-0004


CVE

cve_id:CVE-2015-7925

Trust: 1.4

cve_id:CVE-2015-7926

Trust: 0.8

cve_id:CVE-2015-7929

Trust: 0.8

cve_id:CVE-2015-7927

Trust: 0.8

cve_id:CVE-2015-7928

Trust: 0.8

cve_id:CVE-2015-3970

Trust: 0.3

cve_id:CVE-2015-3967

Trust: 0.3

cve_id:CVE-2015-3969

Trust: 0.3

cve_id:CVE-2015-3968

Trust: 0.3

cve_id:CVE-2015-3973

Trust: 0.3

cve_id:CVE-2015-3971

Trust: 0.3

cve_id:CVE-2015-3972

Trust: 0.3

cve_id:CVE-2015-7924

Trust: 0.3

sources: BID: 77291 // BID: 79625 // PACKETSTORM: 135069 // EDBNET: 24386

TITLE

XZERES 442SR Wind Turbine XSS

Trust: 0.6

sources: EDBNET: 82189

AFFECTED PRODUCTS

vendor:ewonmodel:sa industrial routerscope: - version: -

Trust: 0.6

vendor:xzeresmodel:442sr wind turbinescope: - version: -

Trust: 0.5

vendor:ewonmodel:xss csrf session management rbac issuesscope:eqversion:///

Trust: 0.5

vendor:janitzamodel:umgscope:eqversion:6050

Trust: 0.3

vendor:janitzamodel:umgscope:eqversion:6040

Trust: 0.3

vendor:janitzamodel:umgscope:eqversion:5110

Trust: 0.3

vendor:janitzamodel:umgscope:eqversion:5090

Trust: 0.3

vendor:janitzamodel:umgscope:eqversion:5080

Trust: 0.3

vendor:ewonmodel:ewonscope:eqversion:0

Trust: 0.3

vendor:ewonmodel:10.1s0scope:neversion: -

Trust: 0.3

sources: BID: 77291 // BID: 79625 // PACKETSTORM: 135067 // PACKETSTORM: 135069 // EDBNET: 82186

EXPLOIT

XZERES 442SR Wind Turbine Cross-site Scripting Vulnerability

*AFFECTED PRODUCTS*
XZERES is a US-based energy company that maintains offices in several
countries around the world, including the UK, Italy, Japan, Vietnam,
Philippines, and Myanmar.

The affected product, 442SR Wind Turbine, has a web-based interface system.
According to XZERES, the 442SR is deployed across the Energy sector. XZERES
estimates that this product is used worldwide.

*Reference*
https://ics-cert.us-cert.gov/advisories/ICSA-15-342-01

*Vulnerable parameter*
id

*PoC*

http://<IP>/details?object=Inverter&id=2<script>alert(xss-id-parameter")
</script>
--
Best Regards,
Karn Ganeshen

Trust: 0.6

sources: EDBNET: 82189

PRICE

free

Trust: 0.6

sources: EDBNET: 82189

TYPE

Input Validation Error

Trust: 0.6

sources: BID: 77291 // BID: 79625

TAGS

tag:exploit

Trust: 1.0

tag:xss

Trust: 1.0

tag:vulnerability

Trust: 0.5

tag:csrf

Trust: 0.5

sources: PACKETSTORM: 135067 // PACKETSTORM: 135069

EXTERNAL IDS

db:ICS CERTid:ICSA-15-342-01

Trust: 2.2

db:NVDid:CVE-2015-7925

Trust: 1.4

db:NVDid:CVE-2015-7926

Trust: 0.8

db:NVDid:CVE-2015-7929

Trust: 0.8

db:NVDid:CVE-2015-7927

Trust: 0.8

db:NVDid:CVE-2015-7928

Trust: 0.8

db:ICS CERTid:ICSA-15-351-03

Trust: 0.6

db:EDBNETid:82189

Trust: 0.6

db:EDBNETid:82186

Trust: 0.6

db:0DAYTODAYid:24788

Trust: 0.6

db:EDBNETid:24386

Trust: 0.6

db:PACKETSTORMid:135067

Trust: 0.5

db:PACKETSTORMid:135069

Trust: 0.5

db:ICS CERTid:ICSA-15-265-03

Trust: 0.3

db:NVDid:CVE-2015-3970

Trust: 0.3

db:NVDid:CVE-2015-3967

Trust: 0.3

db:NVDid:CVE-2015-3969

Trust: 0.3

db:NVDid:CVE-2015-3968

Trust: 0.3

db:NVDid:CVE-2015-3973

Trust: 0.3

db:NVDid:CVE-2015-3971

Trust: 0.3

db:NVDid:CVE-2015-3972

Trust: 0.3

db:BIDid:77291

Trust: 0.3

db:NVDid:CVE-2015-7924

Trust: 0.3

db:BIDid:79625

Trust: 0.3

sources: BID: 77291 // BID: 79625 // PACKETSTORM: 135067 // PACKETSTORM: 135069 // EDBNET: 82189 // EDBNET: 82186 // EDBNET: 24386

REFERENCES

url:https://www.intelligentexploit.com

Trust: 1.2

url:https://nvd.nist.gov/vuln/detail/cve-2015-7925

Trust: 1.1

url:https://ics-cert.us-cert.gov/advisories/icsa-15-351-03

Trust: 0.6

url:http://ewon.biz

Trust: 0.6

url:https://0day.today/exploits/24788

Trust: 0.6

url:https://nvd.nist.gov/vuln/detail/cve-2015-7928

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2015-7927

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2015-7926

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2015-7929

Trust: 0.5

url:https://ics-cert.us-cert.gov/advisories/icsa-15-265-03

Trust: 0.3

sources: BID: 77291 // BID: 79625 // PACKETSTORM: 135069 // EDBNET: 82189 // EDBNET: 82186 // EDBNET: 24386

SOURCES

db:BIDid:77291
db:BIDid:79625
db:PACKETSTORMid:135067
db:PACKETSTORMid:135069
db:EDBNETid:82189
db:EDBNETid:82186
db:EDBNETid:24386

LAST UPDATE DATE

2022-07-27T09:47:19.903000+00:00


SOURCES UPDATE DATE

db:BIDid:77291date:2015-10-22T00:00:00
db:BIDid:79625date:2015-12-17T00:00:00

SOURCES RELEASE DATE

db:BIDid:77291date:2015-10-22T00:00:00
db:BIDid:79625date:2015-12-17T00:00:00
db:PACKETSTORMid:135067date:2015-12-24T20:29:23
db:PACKETSTORMid:135069date:2015-12-24T20:35:19
db:EDBNETid:82189date:2015-12-24T00:00:00
db:EDBNETid:82186date:2015-12-24T00:00:00
db:EDBNETid:24386date:2015-12-28T00:00:00