CVE-2021-22714
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD
Description
A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION7400, PM8000 and ION9000 (All versions prior to V3.0.0), which could cause the meter to reboot or allow for remote code execution.
Affected (3)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0.0 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Powerlogic Ion7400 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0.0 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Powerlogic Pm8000 | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.0.0 |
| Running on/with | Platform Versions |
|---|---|
Schneider Electric Powerlogic Ion9000 | All versions |
References (2)
Source: cybersecurity@se.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.