SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-22763

A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could allow an attacker…

CRITICAL 9.8EPSS 1.86%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.86%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could allow an attacker administrator level access to a device.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
1.86% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-640
Affected
schneider-electric/powerlogic pm5560 firmware · schneider-electric/powerlogic pm5561 firmware · schneider-electric/powerlogic pm5562 firmware · schneider-electric/powerlogic pm5563 firmware · schneider-electric/powerlogic pm8ecc firmware
Source
cybersecurity@se.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.