Authorization Bypass in Schneider Electric's MGE Network Management Card
CVE-2018-7243

9.8CRITICAL

Summary

An authorization bypass vulnerability in Schneider Electric's 66074 MGE Network Management Card enables remote attackers to gain full access to the device. By exploiting this vulnerability through the integrated web server on standard ports, attackers can bypass the device's authorization mechanisms, leading to the risk of unauthorized control and potential data exposure.

Affected Version(s)

66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS MGE Network Management Card Transverse, part number: SF66074. All card versions affected, when installed in following products: MGE Galaxy 5000, MGE Galaxy 6000, MGE Galaxy 9000, MGE EPS 7000, MGE EPS 8000, MGE EPS 6000, MGE Comet UPS, MGE Galaxy PW, MGE Galaxy 3000, MGE Galaxy 4000

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.