CVE-2022-46680
published 2023-05-22CVE-2022-46680: A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, denial of service, or…
PriorityP342critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.38%
30.0th percentile
A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could
cause disclosure of sensitive information, denial of service, or modification of data if an attacker
is able to intercept network traffic.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | powerlogic_ion7400_firmware | < 4.0.0 | 4.0.0 |
| schneider-electric | powerlogic_ion9000_firmware | < 4.0.0 | 4.0.0 |
| schneider-electric | powerlogic_pm8000_firmware | < 4.0.0 | 4.0.0 |
| schneider_electric | legacy_ion_products | — | — |
| schneider_electric | powerlogic_ion7400 | — | — |
| schneider_electric | powerlogic_ion8650 | — | — |
| schneider_electric | powerlogic_ion8800 | — | — |
| schneider_electric | powerlogic_ion9000 | — | — |
| schneider_electric | powerlogic_pm8000 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Schneider Electric PowerLogic ION7400 / PM8000 / ION8650 / ION8800 / ION9000 Power Meters
cisa_ics·2023-08-17·CVSS 8.8
[HIGH] Schneider Electric PowerLogic ION7400 / PM8000 / ION8650 / ION8800 / ION9000 Power Meters
ICS Advisory
##
Schneider Electric PowerLogic ION7400 / PM8000 / ION8650 / ION8800 / ION9000 Power Meters
Release DateAugust 17, 2023
Alert CodeICSA-23-229-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Schneider Electric
- Equipment: PowerLogic ION7400 / PM8000 / ION8650 / ION8800 / ION9000
- Vulnerability: Cleartext Transmission of Sensitive Information
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to cause a disclosure of sensitive information, a denial of service, or modification of data if an attacker is able to intercept network traffic.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following components of Schneider Electric PowerLogic,
GHSA
GHSA-fhxw-qvv7-c595: A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could
cause disclosure of sensitive information, denial of servic
ghsa_unreviewed·2023-05-22
CVE-2022-46680 [CRITICAL] CWE-319 GHSA-fhxw-qvv7-c595: A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could
cause disclosure of sensitive information, denial of servic
A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could
cause disclosure of sensitive information, denial of service, or modification of data if an attacker
is able to intercept network traffic.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-05-22
Published