cbcvebase.
CVE-2021-22763
published 2021-06-11

CVE-2021-22763: A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and…

PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.84%
76.5th percentile
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could allow an attacker administrator level access to a device.

Affected

4 ranges
VendorProductVersion rangeFixed in
schneider-electricpowerlogic_pm5560_firmware< 2.7.82.7.8
schneider-electricpowerlogic_pm5561_firmware< 10.7.310.7.3
schneider-electricpowerlogic_pm5562_firmware<= 2.5.4
schneider-electricpowerlogic_pm5563_firmware< 2.7.82.7.8

Detection & IOCsextracted from sources · hover to see the quote

  • Block or monitor HTTP access to PowerLogic PM55xx and PM8ECC devices; exploitation occurs over HTTP (web service) remotely with no authentication required
  • CVE-2021-22763 targets the password recovery mechanism on PowerLogic PM5560/5561/5562/5563/PM8ECC; monitor for unauthenticated password-reset or recovery requests to these devices over the network
  • Exploitation is remotely achievable with high complexity (CVSS AC:H) and no privileges or user interaction; alert on unexpected administrative logins to PowerLogic devices following network-level password-recovery traffic
  • ·PM5560 versions prior to v2.7.8 are vulnerable; patch target is v2.8.3
  • ·PM5561 versions prior to v10.7.3 are vulnerable; patch target is v10.7.3
  • ·PM5562 v2.5.4 and prior are vulnerable; patch target is v4.3.5
  • ·PM5563 versions prior to v2.7.8 are vulnerable; patch target is v2.8.3
  • ·PM8ECC is end-of-service with no patch available; all versions remain vulnerable

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.