Improper Restriction of Operations in PowerLogic Meters by Schneider Electric
CVE-2021-22713

7.5HIGH

Summary

A vulnerability has been identified in Schneider Electric's PowerLogic meters, where improper restrictions on memory buffer operations can lead to unintended behavior, including potential system reboots. This issue arises from inadequate checks on memory boundaries, which could be exploited to disrupt normal meter operations. Users of affected models should take necessary precautions as detailed in the security notification.

Affected Version(s)

PowerLogic ION8650, ION8800, ION7650, ION7700/73xx, and ION83xx/84xx/85xx/8600 (see security notifcation for affected ) PowerLogic ION8650, ION8800, ION7650, ION7700/73xx, and ION83xx/84xx/85xx/8600 (see security notifcation for affected versions)

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.