Back

HIGH

Nordex NC2 Cross-site Scripting

Published Nov 5, 2014

Description

Cross-site scripting (XSS) vulnerability in the login script in the Wind Farm Portal on Nordex Control 2 (NC2) SCADA devices 15 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter.

Affected products

Remediation

Vendor solution

Nordex will release a patch for all affected NC2-SCADA versions until the end of 2014. The patching of the NC2-SCADA system has to be done by Nordex.

Nordex will upgrade all wind farms with a valid service contract to the patched version of the NC2-SCADA in coordination with normal maintenance operations.

Owners of Nordex NC2-based wind farms without a valid service contract can order the patch from Nordex by contacting their local Nordex service organization.

Metrics

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Nov 5, 2014
Updated Nov 3, 2025
Reserved Aug 22, 2014
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a