CVE-2024-10498

MEDIUM

Schneider Electric PowerLogic HDPM6000 - Memory Corruption via Modbus Write Packets

Title source: llm
STIX 2.1

Description

CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow an unauthorized attacker to modify configuration values outside of the normal range when the attacker sends specific Modbus write packets to the device which could result in invalid data or loss of web interface functionality.

Scores

CVSS v3 6.5
EPSS 0.0042
EPSS Percentile 33.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-119
Status published
Products (1)
Schneider Electric/PowerLogic HDPM6000 Versions v0.62.7 and prior
Published Jan 17, 2025
Tracked Since Feb 18, 2026