Improper Authorization Vulnerability in Schneider Electric's MGE Network Management Card
CVE-2018-7245
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 18 April 2018
Summary
An improper authorization issue has been identified in Schneider Electric's MGE Network Management Card Transverse, which is part of the MGE UPS and MGE STS products. This vulnerability could allow a remote attacker to access the integrated web server that operates on Port 80/443/TCP. By exploiting this flaw, attackers could potentially change critical UPS control settings and shutdown parameters without the proper authorization, leading to significant security risks for the affected devices.
Affected Version(s)
66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS MGE Network Management Card Transverse, part number: SF66074. All card versions affected, when installed in following products: MGE Galaxy 5000, MGE Galaxy 6000, MGE Galaxy 9000, MGE EPS 7000, MGE EPS 8000, MGE EPS 6000, MGE Comet UPS, MGE Galaxy PW, MGE Galaxy 3000, MGE Galaxy 4000
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved