Schneider Electric SE Vulnerabilities and Affected Products
Vulnerabilities associated with 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS.
Products
Clear product- U.Motion20 vulnerabilities
- Pelco Sarix Professional12 vulnerabilities
- Embedded Web Servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR02008 vulnerabilities
- 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS4 vulnerabilities
- Citect Anywhere4 vulnerabilities
- IIoT Monitor 3.1.384 vulnerabilities
- Modicon M221, all references, all versions prior to firmware V1.6.2.04 vulnerabilities
- Modicon M5804 vulnerabilities
- PowerSCADA Anywhere4 vulnerabilities
- U.motion Builder4 vulnerabilities
- Eurotherm by Schneider Electric GUIcon V2.0 (Gold Build 683.0)3 vulnerabilities
- EVLink Parking v3.2.0-12_v1 and earlier3 vulnerabilities
- Modicon M3403 vulnerabilities
- Modicon M580, Modicon M340, Modicon Quantum, Modicon Premium (see security notification for specific versions)3 vulnerabilities
- Modicon Quantum3 vulnerabilities
- Pelco Sarix Professional V13 vulnerabilities
- Pelco VideoXpert Enterprise3 vulnerabilities
- Ampla MES2 vulnerabilities
- BMXNOR0200H Ethernet / Serial RTU module2 vulnerabilities
- ClearSCADA2 vulnerabilities
- Modicon Premium2 vulnerabilities
- Modicon Premium, Modicon Quantum, Modicon M340, BMXNOR02002 vulnerabilities
- SoMachine HVAC Programming Software2 vulnerabilities
- U.motion Server2 vulnerabilities
- Wiser for KNX2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-7244MEDIUM | An information disclosure vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to obtain sensitive device information if network access was obtained. CWE-200Apr 18, 2018 | CVSS5.3v3.0 | EPSS1.06% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-7243CRITICAL | An authorization bypass vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to get a full access to device, bypassing the authorization system. Apr 18, 2018 | CVSS9.8v3.0 | EPSS2.83% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-7246CRITICAL | A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. he integrated web server (Port 80/443/TCP) of the affected devices could allow remote attackers to discover an administrative account. If default on device, it is not using a SSL in settings and if multiple request of the page "Access Control" (IP-address device/ups/pas_cont.htm) account data will be sent in cleartext CWE-319Apr 18, 2018 | CVSS9.8v3.0 | EPSS0.852% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2018-7245CRITICAL | An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to change UPS control and shutdown parameters or other critical settings without authorization. CWE-863Apr 18, 2018 | CVSS9.1v3.0 | EPSS1.26% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |