QID 590786

Date Published: 2022-04-12

QID 590786: Schneider Electric PowerLogic PM55xx and PowerLogic PM8ECC Multiple Vulnerabilities (SEVD-2021-159-02)

Affected Products and Versions
PM5560 Versions prior to V2.7.8
PM5561 Versions prior to V10.7.3
PM5562 V2.5.4 and prior
PM5563 Versions prior to 2.7.8
PM8ECC All versions

QID Detection Logic (Authenticated):
The QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities may risk elevation of privileges, which could result in loss of control of the affected device.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SEVD-2021-159-02 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590786

    Software Advisories
    Advisory ID Software Component Link
    SEVD-2021-159-02 URL Logo www.se.com/ww/en/download/document/SEVD-2021-159-02/