SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-22764

A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could cause loss of connectivity to the device via Modbus…

MEDIUM 5.3EPSS 1.87%

Does this matter?

Lower severity and a low EPSS score (1.87%). Track it; it rarely justifies an emergency change on its own.

Description

A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could cause loss of connectivity to the device via Modbus TCP protocol when an attacker sends a specially crafted HTTP request.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS
1.87% probability · 78th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
schneider-electric/powerlogic pm5560 firmware · schneider-electric/powerlogic pm5561 firmware · schneider-electric/powerlogic pm5562 firmware · schneider-electric/powerlogic pm5563 firmware
Source
cybersecurity@se.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.