Insufficient Session Expiration in PME from Schneider Electric
CVE-2023-28003
6.7MEDIUM
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 18 April 2023
What is CVE-2023-28003?
A vulnerability has been identified in PME, where an insufficient session expiration issue allows an attacker to exploit a hijacked session, retaining unauthorized access even after the legitimate user has logged out. This vulnerability raises concerns regarding user privacy and data security, emphasizing the need for robust session management practices to protect sensitive information from unauthorized access.
Affected Version(s)
EcoStruxure Power Monitoring Expert All