QID 590482
Date Published: 2021-08-10
QID 590482: Schneider Electric PowerLogic PM5560 Cross Protocol Injection Vulnerability(ICSA-18-240-03)
AFFECTED PRODUCTS
The following versions of PowerLogic PM5560, a power management system, are affected:
PowerLogic PM5560 all versions prior to firmware Version 2.5.4
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
Successful exploitation of this vulnerability could allow user input to be manipulated, allowing for remote code execution.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-18-240-03 for affected packages and patching details.
Vendor References
- ICSA-18-240-03 -
www.us-cert.gov/ics/advisories/ICSA-18-240-03
CVEs related to QID 590482
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-18-240-03 |
|