PT-2017-8782 · Schneider Electric · Ion8800+6

Published

2017-02-13

·

Updated

2017-03-14

·

CVE-2016-5815

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Schneider Electric IONXXXX series power meters versions (affected versions not specified) Schneider Electric ION73XX series power meters versions (affected versions not specified) Schneider Electric ION75XX series power meters versions (affected versions not specified) Schneider Electric ION76XX series power meters versions (affected versions not specified) Schneider Electric ION8650 series power meters versions (affected versions not specified) Schneider Electric ION8800 series power meters versions (affected versions not specified) Schneider Electric PM5XXX series power meters versions (affected versions not specified)
Description The issue is related to the lack of default authentication configuration, allowing unauthorized users to access the device management portal and make configuration changes.
Recommendations For Schneider Electric IONXXXX series power meters, configure authentication to restrict access to the device management portal. For Schneider Electric ION73XX series power meters, configure authentication to restrict access to the device management portal. For Schneider Electric ION75XX series power meters, configure authentication to restrict access to the device management portal. For Schneider Electric ION76XX series power meters, configure authentication to restrict access to the device management portal. For Schneider Electric ION8650 series power meters, configure authentication to restrict access to the device management portal. For Schneider Electric ION8800 series power meters, configure authentication to restrict access to the device management portal. For Schneider Electric PM5XXX series power meters, configure authentication to restrict access to the device management portal.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-5815

Affected Products

Ion73Xx
Ion75Xx
Ion76Xx
Ion8650
Ion8800
Ionxxxx
Pm5Xxx