First published: Wed Apr 18 2018(Updated: )
An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to change UPS control and shutdown parameters or other critical settings without authorization.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric MGE Network Management Card Transverse | ||
Schneider Electric MGE Comet UPS | ||
Schneider Electric MGE EPS 6000 | ||
Schneider Electric MGE EPS 7000 | ||
Schneider Electric MGE EPS 8000 | ||
Schneider Electric MGE Galaxy 3000 | ||
Schneider Electric MGE Galaxy 4000 | ||
Schneider Electric MGE Galaxy 5000 | ||
Schneider Electric MGE Galaxy 6000 | ||
Schneider Electric MGE Galaxy 9000 | ||
Schneider Electric MGE Galaxy PW |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-7245 has been reported with a medium severity level.
To fix CVE-2018-7245, it is recommended to update the affected Schneider Electric devices with the latest security patches.
CVE-2018-7245 affects the Schneider Electric 66074 MGE Network Management Card Transverse.
Attackers exploiting CVE-2018-7245 could change UPS control and shutdown parameters remotely.
Yes, CVE-2018-7245 is classified as an improper authorization vulnerability.