PT-2021-3888 · Schneider Electric · Powerlogic Ion84Xx+9

Published

2021-02-09

·

Updated

2026-05-29

·

CVE-2021-22701

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000, PM800 (affected versions not specified)
Description The issue is related to insufficient authentication of executed requests, which could allow a remote attacker to perform a cross-site request forgery. This might cause a user to perform an unintended action on the target device when using the HTTP web interface.
Recommendations For PowerLogic ION7400, consider disabling access to the HTTP web interface until a patch is available. For PowerLogic ION7650, restrict access to the web interface to minimize the risk of exploitation. For PowerLogic ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000, and PM800, avoid using the web interface for critical operations until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Weakness Enumeration

Related Identifiers

BDU:2021-04269
CVE-2021-22701

Affected Products

Pm800
Powerlogic Ion7400
Powerlogic Ion7650
Powerlogic Ion83Xx
Powerlogic Ion84Xx
Powerlogic Ion85Xx
Powerlogic Ion8600
Powerlogic Ion8650
Powerlogic Ion8800
Powerlogic Ion9000