QID 590519

Date Published: 2021-10-14

QID 590519: Schneider Electric Enerlin'X ComX 510 Improper Privilege Management Vulnerability (ICSA-21-168-01)

AFFECTED PRODUCTS
The following versions of Enerlin'X ComX 510 energy servers are affected:
Enerlin'X ComX 510: All versions prior to v6.8.4

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of this vulnerability could allow elevation of privileges, which could result in unintended disclosure of device configuration information to any authenticated user.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-168-01 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590519

    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-168-01 URL Logo www.us-cert.gov/ics/advisories/ICSA-21-168-01