PT-2023-3317 · Schneider Electric · Powerlogic Pm8000+4
Published
2023-05-09
·
Updated
2023-05-27
·
CVE-2022-46680
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Schneider Electric PowerLogic ION9000 versions (affected versions not specified)
Schneider Electric PowerLogic ION7400 versions (affected versions not specified)
Schneider Electric PowerLogic PM8000 versions (affected versions not specified)
Schneider Electric PowerLogic ION8650 versions (affected versions not specified)
Schneider Electric PowerLogic ION8800 versions (affected versions not specified)
Description
A vulnerability exists that could cause disclosure of sensitive information, denial of service, or modification of data if an attacker is able to intercept network traffic. This issue is related to the transmission of sensitive information in cleartext.
Recommendations
For Schneider Electric PowerLogic ION9000, consider implementing encryption for sensitive data transmission until a patch is available.
For Schneider Electric PowerLogic ION7400, restrict access to sensitive information to minimize the risk of exploitation.
For Schneider Electric PowerLogic PM8000, avoid transmitting sensitive information over unsecured networks until the issue is resolved.
For Schneider Electric PowerLogic ION8650, disable any features that transmit sensitive information in cleartext as a temporary workaround.
For Schneider Electric PowerLogic ION8800, apply configuration changes to secure data transmission, such as enabling encryption, until a fix is available.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Powerlogic Ion7400
Powerlogic Ion8650
Powerlogic Ion8800
Powerlogic Ion9000
Powerlogic Pm8000