PT-2021-15176 · Schneider Electric · Powerlogic Ion8800+6
Published
2021-02-19
·
Updated
2026-05-29
·
CVE-2021-22703
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
PowerLogic ION7400 (affected versions not specified)
PowerLogic ION7650 (affected versions not specified)
PowerLogic ION83xx/84xx/85xx/8600 (affected versions not specified)
PowerLogic ION8650 (affected versions not specified)
PowerLogic ION8800 (affected versions not specified)
PowerLogic ION9000 (affected versions not specified)
PowerLogic PM800 (affected versions not specified)
Description
A Cleartext transmission of sensitive information issue exists that could cause disclosure of user credentials when a malicious actor intercepts HTTP network traffic between a user and the device.
Recommendations
For PowerLogic ION7400, consider disabling HTTP network traffic until a secure protocol is implemented.
For PowerLogic ION7650, restrict access to sensitive information to minimize the risk of exploitation.
For PowerLogic ION83xx/84xx/85xx/8600, avoid using cleartext transmission of sensitive information until a patch is available.
For PowerLogic ION8650, consider implementing a secure protocol for network traffic.
For PowerLogic ION8800, restrict access to user credentials to minimize the risk of exploitation.
For PowerLogic ION9000, consider disabling the use of HTTP for sensitive information transmission until a secure protocol is implemented.
For PowerLogic PM800, avoid using cleartext transmission of sensitive information until a patch is available.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Powerlogic Ion7400
Powerlogic Ion7650
Powerlogic Ion83Xx/84Xx/85Xx/8600
Powerlogic Ion8650
Powerlogic Ion8800
Powerlogic Ion9000
Powerlogic Pm800