QID 590789

Date Published: 2022-04-12

QID 590789: Schneider Electric Sepam ACE850 Treck Hypertext Transfer Protocol Server (HTTP Server) Vulnerability (SEVD-2021-012-03)

Affected Products and Versions
ACE850 Sepam communication interface All versions

QID Detection Logic (Authenticated):
The QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities may risk heap-based buffer overflow, which could result in denial of service of the web server or remote code execution.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SEVD-2021-012-03 for affected packages and patching details.

    Vendor References

    CVEs related to QID 590789

    Software Advisories
    Advisory ID Software Component Link