PT-2024-10218 · Schneider Electric · Schneider Electric Powerlogic Hdpm6000
Published
2024-10-29
·
Updated
2025-02-07
·
CVE-2024-10497
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Schneider Electric PowerLogic HDPM6000 version 0.62.7
Description
The issue is related to an authorization bypass vulnerability that could allow an authorized attacker to modify values outside those defined by their privileges, potentially leading to elevation of privileges. This can be achieved by sending modified HTTPS requests to the device. The vulnerability is associated with a user-controlled key. It may affect a significant number of internet users.
Recommendations
For Schneider Electric PowerLogic HDPM6000 version 0.62.7, consider disabling the use of user-controlled keys until a patch is available. Restrict access to the device to minimize the risk of exploitation. Avoid using modified HTTPS requests to the device until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Schneider Electric Powerlogic Hdpm6000