CVE-2018-7245

CRITICAL

Schneider Electric 66074 MGE Network Management Card Transverse - Unauthenticated Parameter Modification via Web Server

Title source: llm
STIX 2.1

Description

An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to change UPS control and shutdown parameters or other critical settings without authorization.

References (1)

Core 1
Core References
Mitigation, Vendor Advisory x_refsource_confirm
https://www.schneider-electric.com/en/download/document/SEVD-2018-074-01/

Scores

CVSS v3 9.1
EPSS 0.0043
EPSS Percentile 63.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-863
Status published
Products (1)
schneider-electric/66074_mge_network_management_card_transverse
Published Apr 18, 2018
Tracked Since Feb 18, 2026