CVE-2021-22764 PUBLISHED CVSS 5.300000190734863 MEDIUM

A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could cause loss of connectivity to the device via Modbus TCP protocol when an attacker sends a specially crafted HTTP request.

EPSS 0.25% · 48.0th percentile

Risk Scores

CVSS v3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Score
0.25%
48.0th percentile

Affected Products

VendorProductVersions
schneider-electricpowerlogic_pm5562_firmware0
schneider-electricpowerlogic_pm5561_firmware0
schneider-electricpowerlogic_pm5560_firmware0
schneider-electricpowerlogic_pm5563_firmware0
n/aPowerLogic PM55xx, PowerLogic EGX100, and PowerLogic EGX300 (see security notification for version infromation)PowerLogic PM55xx, PowerLogic EGX100, and PowerLogic EGX300 (see security notification for version infromation)

Timeline

References

Open in Interactive Console →