CVE-2018-7797: Medium severity schneider electric ecostruxure energy expert vulnerability
A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module, EcoStruxure Power Monitoring Expert (PME) v9.0, EcoStruxure Energy Expert v2.0, and EcoStruxure Power SCADA Operation (PSO) 9.0 Advanced Reports and Dashboards Module which could cause a phishing attack when redirected to a malicious site.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-7797?
CVE-2018-7797 is a URL redirection vulnerability that exists in Power Monitoring Expert, Energy Expert, EcoStruxure Power SCADA Operation, and EcoStruxure Power Monitoring Expert.
What is the severity of CVE-2018-7797?
CVE-2018-7797 has a severity rating of 6.1 (medium).
Which software versions are affected by CVE-2018-7797?
CVE-2018-7797 affects EcoStruxure Energy Expert 1.3, EcoStruxure Energy Expert 2.0, EcoStruxure Power Monitoring Expert 8.2, EcoStruxure Power Monitoring Expert 9.0, EcoStruxure Power SCADA Operation 8.2, and EcoStruxure Power SCADA Operation 9.0.
How can I fix CVE-2018-7797?
To fix CVE-2018-7797, it is recommended to apply the necessary security patches provided by Schneider Electric or upgrade to the latest version of the affected software.
Where can I find more information about CVE-2018-7797?
More information about CVE-2018-7797 can be found at the following references: [SecurityFocus](http://www.securityfocus.com/bid/106277) and [Schneider Electric Advisory](https://www.schneider-electric.com/en/download/document/SEVD-2018-347-01/).