PT-2024-10219 · Schneider Electric · Powerlogic Hdpm6000
Published
2024-10-29
·
Updated
2025-01-17
·
CVE-2024-10498
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Schneider Electric PowerLogic HDPM6000 versions up to 0.62.7
Description
The issue is related to an Improper Restriction of Operations within the Bounds of a Memory Buffer, which could allow an unauthorized attacker to modify configuration values outside of the normal range by sending specific Modbus write packets to the device. This could result in invalid data or loss of web interface functionality.
Recommendations
For Schneider Electric PowerLogic HDPM6000 versions up to 0.62.7, consider disabling the Modbus protocol until a patch is available to prevent exploitation.
Restrict access to the device to minimize the risk of unauthorized configuration modifications.
Avoid using the Modbus write packets to the device until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Powerlogic Hdpm6000