CVE-2021-22764
published 2021-06-11CVE-2021-22764: A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security…
PriorityP433medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
1.86%
76.7th percentile
A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could cause loss of connectivity to the device via Modbus TCP protocol when an attacker sends a specially crafted HTTP request.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | powerlogic_pm5560_firmware | < 2.7.8 | 2.7.8 |
| schneider-electric | powerlogic_pm5561_firmware | < 10.7.3 | 10.7.3 |
| schneider-electric | powerlogic_pm5562_firmware | <= 2.5.4 | — |
| schneider-electric | powerlogic_pm5563_firmware | < 2.7.8 | 2.7.8 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric PowerLogic PM55xx and PowerLogic PM8ECC
cisa_ics·2024-11-26·CVSS 9.8
[CRITICAL] Schneider Electric PowerLogic PM55xx and PowerLogic PM8ECC
ICS Advisory
##
Schneider Electric PowerLogic PM55xx and PowerLogic PM8ECC
Release DateNovember 26, 2024
Alert CodeICSA-24-331-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.5
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Schneider Electric
- Equipment: PowerLogic PM5500 and PowerLogic PM8ECC
- Vulnerabilities: Weak Password Recovery Mechanism for Forgotten Password, Improper Authentication
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in an attacker gaining escalated privileges and obtaining control of the device.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of PowerLogic PM55xx
GHSA
GHSA-57rv-qg24-x8hj: A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security
ghsa_unreviewed·2022-05-24
CVE-2021-22764 [MEDIUM] CWE-287 GHSA-57rv-qg24-x8hj: A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security
A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could cause loss of connectivity to the device via Modbus TCP protocol when an attacker sends a specially crafted HTTP request.
No detection rules found.
No public exploits indexed.
2021-06-11
Published