CVE-2021-22713
published 2021-03-11CVE-2021-22713: A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION8650, ION8800, ION7650, ION7700/73xx…
PriorityP277high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
1.19%
64.2th percentile
A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION8650, ION8800, ION7650, ION7700/73xx, and ION83xx/84xx/85xx/8600 (see security notifcation for affected versions), which could cause the meter to reboot.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | ion7650_firmware | < 416 | 416 |
| schneider-electric | powerlogic_ion7550_firmware | < 376 | 376 |
| schneider-electric | powerlogic_ion7550_firmware | < 416 | 416 |
| schneider-electric | powerlogic_ion7650_firmware | < 376 | 376 |
| schneider-electric | powerlogic_ion8650_firmware | < 4.40.1 | 4.40.1 |
| schneider-electric | powerlogic_ion8800_firmware | < 372 | 372 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
vulncheck7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fp3q-76ww-6mv4: A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION8650, ION8800, ION7650, ION770
ghsa_unreviewed·2022-05-24
CVE-2021-22713 [HIGH] CWE-119 GHSA-fp3q-76ww-6mv4: A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION8650, ION8800, ION7650, ION770
A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION8650, ION8800, ION7650, ION7700/73xx, and ION83xx/84xx/85xx/8600 (see security notifcation for affected versions), which could cause the meter to reboot.
VulnCheck
Schneider Electric powerlogic_ion8650_firmware Improper Restriction of Operations within the Bounds of a Memory Buffer
vulncheck·2021·CVSS 7.5
CVE-2021-22713 [HIGH] Schneider Electric powerlogic_ion8650_firmware Improper Restriction of Operations within the Bounds of a Memory Buffer
Schneider Electric powerlogic_ion8650_firmware Improper Restriction of Operations within the Bounds of a Memory Buffer
A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION8650, ION8800, ION7650, ION7700/73xx, and ION83xx/84xx/85xx/8600 (see security notifcation for affected versions), which could cause the meter to reboot.
Affected: Schneider Electric powerlogic_ion8650_firmware
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://blog.cloudflare.com/ddos-threat-report-2023-q1/
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-03-11
Published
Exploited in the wild