PT-2024-10219 · Schneider Electric · Powerlogic Hdpm6000

Published

2024-10-29

·

Updated

2025-01-17

·

CVE-2024-10498

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Schneider Electric PowerLogic HDPM6000 versions up to 0.62.7
Description The issue is related to an Improper Restriction of Operations within the Bounds of a Memory Buffer, which could allow an unauthorized attacker to modify configuration values outside of the normal range by sending specific Modbus write packets to the device. This could result in invalid data or loss of web interface functionality.
Recommendations For Schneider Electric PowerLogic HDPM6000 versions up to 0.62.7, consider disabling the Modbus protocol until a patch is available to prevent exploitation. Restrict access to the device to minimize the risk of unauthorized configuration modifications. Avoid using the Modbus write packets to the device until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-00549
CVE-2024-10498

Affected Products

Powerlogic Hdpm6000