Описание
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series. No authentication is configured by default. An unauthorized user can access the device management portal and make configuration changes.
Ссылки
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryUS Government Resource
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:h:schneider-electric:ion5000:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ion7300:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ion7500:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ion7600:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ion8650:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:ion8800:-:*:*:*:*:*:*:*
EPSS
Процентиль: 78%
0.01186
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-284
Связанные уязвимости
CVSS3: 9.8
github
больше 3 лет назад
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series. No authentication is configured by default. An unauthorized user can access the device management portal and make configuration changes.
EPSS
Процентиль: 78%
0.01186
Низкий
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
CWE-284