CVE-2015-6462: Schneider Electric BMXNOC0401 Firmware

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

Reflected Cross-Site Scripting (nonpersistent) allows an attacker to craft a specific URL, which contains Java script that will be executed on the Schneider Electric Modicon BMXNOC0401, BMXNOE0100, BMXNOE0110, BMXNOE0110H, BMXNOR0200H, BMXP342020, BMXP342020H, BMXP342030, BMXP3420302, BMXP3420302H, or BMXP342030H PLC client browser.

Affected products

Published 2019-03-21. Last modified 2026-06-17.