First published: Mon Feb 13 2017(Updated: )
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series. No authentication is configured by default. An unauthorized user can access the device management portal and make configuration changes.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Ion5000 | ||
Schneider-electric Ion7300 | ||
Schneider Electric Ion7500 | ||
Schneider Electric ION7600 | ||
Schneider-electric Ion8650 Firmware | ||
Schneider-electric Ion8800 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-5815 is classified as a high-severity vulnerability due to the lack of authentication allowing unauthorized device access.
To fix CVE-2016-5815, enable authentication on affected Schneider Electric power meters to secure the device management portal.
CVE-2016-5815 affects Schneider Electric IONXXXX series meters, including ION73XX, ION75XX, ION76XX, ION8650, ION8800, and PM5XXX series.
An attacker exploiting CVE-2016-5815 could access and modify device configurations without any authentication.
Currently, there is no public patch available for CVE-2016-5815, but securing device settings is essential to mitigate the risk.