CVE-2021-22713
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION8650, ION8800, ION7650, ION7700/73xx, and ION83xx/84xx/85xx/8600 (see security notifcation for affected versions), which could cause the meter to reboot.
Affected (12)
Products: Schneider Electric: Powerlogic Ion8650 Firmware, Powerlogic Ion8800 Firmware, Powerlogic Ion7550 Firmware, Powerlogic Ion7650 Firmware, Powerlogic Ion7700 Firmware, Powerlogic Ion7300 Firmware, Powerlogic Ion8300 Firmware, Powerlogic Ion8400 Firmware, Powerlogic Ion8500 Firmware, Powerlogic Ion8600 Firmware, Ion7650 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 4.40.1 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Powerlogic Ion8650 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 372 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Powerlogic Ion8800 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 376 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Powerlogic Ion7550 | Version 4.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 376 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Powerlogic Ion7650 | Version 4.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Powerlogic Ion7700 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Powerlogic Ion7300 | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Powerlogic Ion8300 | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Powerlogic Ion8400 | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Powerlogic Ion8500 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Powerlogic Ion8600 | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 416 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Powerlogic Ion7550 | Version 5.0 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 416 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Powerlogic Ion7650 | Version 5.0 |
References (2)
Source: cybersecurity@se.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.