First published: Wed Apr 18 2018(Updated: )
An information disclosure vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to obtain sensitive device information if network access was obtained.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric MGE Network Management Card Transverse | ||
Schneider Electric MGE Comet UPS | ||
Schneider Electric MGE EPS 6000 | ||
Schneider Electric MGE EPS 7000 | ||
Schneider Electric MGE EPS 8000 | ||
Schneider Electric MGE Galaxy 3000 | ||
Schneider Electric MGE Galaxy 4000 | ||
Schneider Electric MGE Galaxy 5000 | ||
Schneider Electric MGE Galaxy 6000 | ||
Schneider Electric MGE Galaxy 9000 | ||
Schneider Electric MGE Galaxy PW |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7244 is rated as a medium severity vulnerability due to the potential information disclosure risk.
To mitigate CVE-2018-7244, it is recommended to upgrade the firmware of the 66074 MGE Network Management Card to the latest version provided by Schneider Electric.
CVE-2018-7244 primarily affects Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS.
Yes, CVE-2018-7244 can be exploited remotely by an attacker accessing the integrated web server of the affected devices.
CVE-2018-7244 allows remote attackers to obtain sensitive device information through the web server of the vulnerable devices.