PT-2021-3888 · Schneider Electric · Powerlogic Ion84Xx+9
Published
2021-02-09
·
Updated
2026-05-29
·
CVE-2021-22701
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:S/C:N/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000, PM800 (affected versions not specified)
Description
The issue is related to insufficient authentication of executed requests, which could allow a remote attacker to perform a cross-site request forgery. This might cause a user to perform an unintended action on the target device when using the HTTP web interface.
Recommendations
For PowerLogic ION7400, consider disabling access to the HTTP web interface until a patch is available.
For PowerLogic ION7650, restrict access to the web interface to minimize the risk of exploitation.
For PowerLogic ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000, and PM800, avoid using the web interface for critical operations until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pm800
Powerlogic Ion7400
Powerlogic Ion7650
Powerlogic Ion83Xx
Powerlogic Ion84Xx
Powerlogic Ion85Xx
Powerlogic Ion8600
Powerlogic Ion8650
Powerlogic Ion8800
Powerlogic Ion9000