Insufficient Session Expiration in PME from Schneider Electric
CVE-2023-28003
6.7MEDIUM
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 18 April 2023
Summary
A vulnerability has been identified in PME, where an insufficient session expiration issue allows an attacker to exploit a hijacked session, retaining unauthorized access even after the legitimate user has logged out. This vulnerability raises concerns regarding user privacy and data security, emphasizing the need for robust session management practices to protect sensitive information from unauthorized access.
Affected Version(s)
EcoStruxure Power Monitoring Expert All
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved