Insufficient Session Expiration in PME from Schneider Electric
CVE-2023-28003

6.7MEDIUM

Key Information:

Vendor
CVE Published:
18 April 2023

Summary

A vulnerability has been identified in PME, where an insufficient session expiration issue allows an attacker to exploit a hijacked session, retaining unauthorized access even after the legitimate user has logged out. This vulnerability raises concerns regarding user privacy and data security, emphasizing the need for robust session management practices to protect sensitive information from unauthorized access.

Affected Version(s)

EcoStruxure Power Monitoring Expert All

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.