Issue:
Is PowerChute Network Shutdown vulnerable to Cross Site Tracing (XST)?
Product:
PowerChute Network Shutdown
Environment:
All support OS
Cause:
Jetty web server
Solution:
The PCNS application is hosted on a Jetty Web Server. By default Jetty appears to have the HTTP TRACE method enabled.
In earlier versions of PowerChute (prior to 4.0), in response to an HTTP OPTIONS request the Jetty Web Server lists TRACE as an available option. However the TRACE method is blocked by the PCNS application.
HTTP/1.1 405 Method Not Allowed is sent in response to any TRACE request. Therefore PCNS is not vulnerable to CrossSite Tracing.
Cross site tracing (XST) is a vulnerability exploiting the HTTP TRACE method.
Further information can be found here:
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
Released for: Schneider Electric Egypt and North East Africa


Need help?
Product Selector
Quickly and easily find the right products and accessories for your applications.
Get a Quote
Start your sales enquiry online and an expert will connect with you.
Where to buy?
Easily find the nearest Schneider Electric distributor in your location.
Help Center
Find support resources for all your needs, in one place.