PT-2023-3317 · Schneider Electric · Powerlogic Pm8000+4

Published

2023-05-09

·

Updated

2023-05-27

·

CVE-2022-46680

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Schneider Electric PowerLogic ION9000 versions (affected versions not specified) Schneider Electric PowerLogic ION7400 versions (affected versions not specified) Schneider Electric PowerLogic PM8000 versions (affected versions not specified) Schneider Electric PowerLogic ION8650 versions (affected versions not specified) Schneider Electric PowerLogic ION8800 versions (affected versions not specified)
Description A vulnerability exists that could cause disclosure of sensitive information, denial of service, or modification of data if an attacker is able to intercept network traffic. This issue is related to the transmission of sensitive information in cleartext.
Recommendations For Schneider Electric PowerLogic ION9000, consider implementing encryption for sensitive data transmission until a patch is available. For Schneider Electric PowerLogic ION7400, restrict access to sensitive information to minimize the risk of exploitation. For Schneider Electric PowerLogic PM8000, avoid transmitting sensitive information over unsecured networks until the issue is resolved. For Schneider Electric PowerLogic ION8650, disable any features that transmit sensitive information in cleartext as a temporary workaround. For Schneider Electric PowerLogic ION8800, apply configuration changes to secure data transmission, such as enabling encryption, until a fix is available.

Fix

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2023-03465
CVE-2022-46680

Affected Products

Powerlogic Ion7400
Powerlogic Ion8650
Powerlogic Ion8800
Powerlogic Ion9000
Powerlogic Pm8000