Information Disclosure Vulnerability in Schneider Electric’s MGE Network Management Card
CVE-2018-7244
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 18 April 2018
Summary
An information disclosure vulnerability exists in Schneider Electric's MGE Network Management Card which is integrated into their MGE UPS and MGE STS systems. This vulnerability can be exploited by a remote attacker who gains network access, allowing them to retrieve sensitive information from the integrated web server operating on TCP ports 80 and 443. Adequate security measures should be implemented to mitigate the risk of unauthorized access to these devices.
Affected Version(s)
66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS MGE Network Management Card Transverse, part number: SF66074. All card versions affected, when installed in following products: MGE Galaxy 5000, MGE Galaxy 6000, MGE Galaxy 9000, MGE EPS 7000, MGE EPS 8000, MGE EPS 6000, MGE Comet UPS, MGE Galaxy PW, MGE Galaxy 3000, MGE Galaxy 4000
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved