S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2015-6477 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Nordex Control 2 (NC2) affects v. 16 and earlier.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
3.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2015-6477
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

Multiple cross-site scripting (XSS) vulnerabilities in the Wind Farm Portal application in Nordex Control 2 (NC2) SCADA 16 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Nordex Control 2 (NC2) is a Supervisory Control and Data Acquisition (SCADA) system used in wind farms to monitor and control wind turbines. The system is designed to maintain optimal performance of wind turbines and to ensure that energy generated from the wind farm is delivered safely to the electrical grid. Nordex Control 2 is a critical component of the wind farm as without it; the performance and security of the whole wind farm may be affected.

One of the vulnerabilities detected in the Nordex Control 2 system is the CVE-2015-6477. This vulnerability occurs when multiple cross-site scripting (XSS) vulnerabilities are uncovered, potentially allowing remote attackers to inject arbitrary web scripts or HTML via unspecified vectors. Exploitation of these vulnerabilities can eventually result in unauthorized access to the SCADA system.

When the vulnerability is exploited, it can lead to severe consequences. Attackers can gain unauthorized access to the SCADA system, manipulate the turbines, and cause system failures, leading to significant losses. Furthermore, the attackers can steal sensitive information, such as operational data, network configurations, and other system-related information, potentially causing further damage to the wind farm.

In conclusion, the Nordex Control 2 (NC2) SCADA system is an essential component of wind farms designed to maintain optimal performance and safety. However, multiple vulnerabilities such as CVE-2015-6477 can create significant issues, with potential consequences ranging from unauthorized access to information theft. By following security best practices, organizations can protect against these vulnerabilities and ensure that their digital assets remain secure. Additionally, the s4e.io platform provides an excellent place to learn about vulnerabilities and stay informed on emerging risks.

 

REFERENCES

Solution Advice

To protect against the CVE-2015-6477 vulnerability, the following precautions can be taken:

  • Update the Nordex Control 2 system to the latest version to mitigate the vulnerability.
  • Ensure that all security patches are installed in a timely manner to stay up to date and remove any known vulnerabilities.
  • Deploy HTTP Content Security Policy (CSP) to keep attackers from injecting malicious scripts.
  • Implement Web Application Firewall (WAF) to filter malicious traffic attempts and protect the application from common exploits.
  • Educate the IT team and employees about emerging vulnerabilities and provide training on how to detect and mitigate them.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2015-6477 scanner - Cross-Site Scripting (XSS) vulnerability in Nordex Control 2 (NC2) | S4E