QID 590923
Date Published: 2022-07-18
QID 590923: Schneider Electric Power Logic PM8ECC Vulnerability (SEVD-2016-271-01)
AFFECTED PRODUCTS
Power Logic PM8ECC, firmware up to 2.651 inclusive
QID Detection Logic (uthenticated):
QID checks for the Vulnerable version of using passive scanning
Navigating a web browser to status.htm may display a special User in the top right corner of the browser window. Using this special user as both username and password to login to the meter via HTTP or FTP will allow full administrator access.
Solution
Customers are advised to refer to CERT MITIGATIONS section SEVD-2016-271-01 for affected packages and patching details.
Vendor References
- SEVD-2016-271-01 -
www.se.com/ww/en/download/document/SEVD-2016-271-01/
CVEs related to QID 590923
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SEVD-2016-271-01 |
|