CVE-2018-19615 is a cross-site scripting (XSS) vulnerability affecting all versions of Rockwell Automation Allen-Bradley PowerMonitor 1000 devices. A remote attacker can inject arbitrary code into a user's web browser, potentially gaining access to the device. With a CVSS score of 6.1 (Medium), this vulnerability requires user interaction and has low impact on confidentiality and integrity, but no impact on availability. There is no evidence of active exploitation, public exploit code, or inclusion in CISA's KEV catalog, though it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1408-em3a-ent_bCPE matchmatch criteria | cpe:2.3:o:rockwellautomation:powermonitor_1000_firmware:1408-em3a-ent_b:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.