CVE-2018-7797
published 2018-12-17CVE-2018-7797: A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all…
PriorityP426medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
0.76%
50.8th percentile
A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module, EcoStruxure Power Monitoring Expert (PME) v9.0, EcoStruxure Energy Expert v2.0, and EcoStruxure Power SCADA Operation (PSO) 9.0 Advanced Reports and Dashboards Module which could cause a phishing attack when redirected to a malicious site.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | ecostruxure_energy_expert | — | — |
| schneider-electric | ecostruxure_energy_expert | — | — |
| schneider-electric | ecostruxure_power_monitoring_expert | — | — |
| schneider-electric | ecostruxure_power_monitoring_expert | — | — |
| schneider-electric | ecostruxure_power_scada_operation | — | — |
| schneider-electric | ecostruxure_power_scada_operation | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9p3j-xx7r-8mm9: A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME)
ghsa_unreviewed·2022-05-14
CVE-2018-7797 [MEDIUM] CWE-601 GHSA-9p3j-xx7r-8mm9: A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME)
A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module, EcoStruxure Power Monitoring Expert (PME) v9.0, EcoStruxure Energy Expert v2.0, and EcoStruxure Power SCADA Operation (PSO) 9.0 Advanced Reports and Dashboards Module which could cause a phishing attack when redirected to a malicious site.
CISA ICS
Schneider Electric EcoStruxure
cisa_ics·2018-12-20·CVSS 6.1
[MEDIUM] Schneider Electric EcoStruxure
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric EcoStruxure
Last RevisedDecember 20, 2018
Alert CodeICSA-18-354-02
## 1. EXECUTIVE SUMMARY
-
CVSS v3 7.4
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Schneider Electric
- Equipment: EcoStruxure
- Vulnerability: Open Redirect
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to use this device as a platform to conduct a phishing attack.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of EcoStruxure, an IoT-enabled architecture and platform, are affected:
- EcoS
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-12-17
Published