Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-5815

Опубликовано: 13 фев. 2017
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series. No authentication is configured by default. An unauthorized user can access the device management portal and make configuration changes.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:h:schneider-electric:ion5000:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ion7300:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ion7500:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ion7600:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ion8650:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ion8800:-:*:*:*:*:*:*:*

EPSS

Процентиль: 78%
0.01186
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series. No authentication is configured by default. An unauthorized user can access the device management portal and make configuration changes.

EPSS

Процентиль: 78%
0.01186
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-284