Improper Authorization Vulnerability in Schneider Electric's MGE Network Management Card
CVE-2018-7245

9.1CRITICAL

Summary

An improper authorization issue has been identified in Schneider Electric's MGE Network Management Card Transverse, which is part of the MGE UPS and MGE STS products. This vulnerability could allow a remote attacker to access the integrated web server that operates on Port 80/443/TCP. By exploiting this flaw, attackers could potentially change critical UPS control settings and shutdown parameters without the proper authorization, leading to significant security risks for the affected devices.

Affected Version(s)

66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS MGE Network Management Card Transverse, part number: SF66074. All card versions affected, when installed in following products: MGE Galaxy 5000, MGE Galaxy 6000, MGE Galaxy 9000, MGE EPS 7000, MGE EPS 8000, MGE EPS 6000, MGE Comet UPS, MGE Galaxy PW, MGE Galaxy 3000, MGE Galaxy 4000

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.