PT-2021-15176 · Schneider Electric · Powerlogic Ion8800+6

Published

2021-02-19

·

Updated

2026-05-29

·

CVE-2021-22703

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PowerLogic ION7400 (affected versions not specified) PowerLogic ION7650 (affected versions not specified) PowerLogic ION83xx/84xx/85xx/8600 (affected versions not specified) PowerLogic ION8650 (affected versions not specified) PowerLogic ION8800 (affected versions not specified) PowerLogic ION9000 (affected versions not specified) PowerLogic PM800 (affected versions not specified)
Description A Cleartext transmission of sensitive information issue exists that could cause disclosure of user credentials when a malicious actor intercepts HTTP network traffic between a user and the device.
Recommendations For PowerLogic ION7400, consider disabling HTTP network traffic until a secure protocol is implemented. For PowerLogic ION7650, restrict access to sensitive information to minimize the risk of exploitation. For PowerLogic ION83xx/84xx/85xx/8600, avoid using cleartext transmission of sensitive information until a patch is available. For PowerLogic ION8650, consider implementing a secure protocol for network traffic. For PowerLogic ION8800, restrict access to user credentials to minimize the risk of exploitation. For PowerLogic ION9000, consider disabling the use of HTTP for sensitive information transmission until a secure protocol is implemented. For PowerLogic PM800, avoid using cleartext transmission of sensitive information until a patch is available.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2021-22703

Affected Products

Powerlogic Ion7400
Powerlogic Ion7650
Powerlogic Ion83Xx/84Xx/85Xx/8600
Powerlogic Ion8650
Powerlogic Ion8800
Powerlogic Ion9000
Powerlogic Pm800