CVE-2021-22764
A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could cause loss of connectivity to the device via Modbus…
Does this matter?
Lower severity and a low EPSS score (1.87%). Track it; it rarely justifies an emergency change on its own.
Description
A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could cause loss of connectivity to the device via Modbus TCP protocol when an attacker sends a specially crafted HTTP request.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- EPSS
- 1.87% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- schneider-electric/powerlogic pm5560 firmware · schneider-electric/powerlogic pm5561 firmware · schneider-electric/powerlogic pm5562 firmware · schneider-electric/powerlogic pm5563 firmware
- Source
- cybersecurity@se.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.