logo

Home is where the XSS is: DHS Warns of Flaw in Building Automation System

ID: 7ec82ecd-638d-5f84-a7d8-24116450f020

STIX ID: report--7ec82ecd-638d-5f84-a7d8-24116450f020

Feed Name: Security Ledger

Threat Score
45/100

Date Published: 2017-01-20

Date Updated: 2026-04-26

Author: Paul Roberts

...
...

The U.S. Department of Homeland Security's ICS-CERT warned of a cross-site scripting (XSS) vulnerability in Schneider Electric's homeLYnk controller (model LSS100100) affecting firmware versions prior to V1.5.0. The flaw allows attacker-supplied JavaScript to execute via the device's embedded web server 404 page; Schneider released updated firmware to remediate the issue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.