CVE-2021-22703: High severity Schneider-electric Powerlogic Ion7400 Firmware vulnerability
A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure of user credentials when a malicious actor intercepts HTTP network traffic between a user and the device.
Affected Software
Event History
Frequently Asked Questions
What are the potential risks of CVE-2021-22703?
CVE-2021-22703 can lead to the exposure of sensitive user credentials due to cleartext transmission over HTTP.
Which software versions are affected by CVE-2021-22703?
CVE-2021-22703 affects various versions of Schneider Electric's PowerLogic ION7400, ION7650, ION8600, ION8650, ION8800, ION9000, and PM800 firmware.
How can organizations mitigate the risk of CVE-2021-22703?
Organizations can mitigate CVE-2021-22703 by ensuring the use of encrypted communication methods such as HTTPS.
How do I check if my device is vulnerable to CVE-2021-22703?
To check for vulnerability to CVE-2021-22703, verify the firmware version of affected Schneider Electric PowerLogic devices against the specified vulnerable versions.
What should I do if I discover my device is affected by CVE-2021-22703?
If your device is affected by CVE-2021-22703, it is recommended to update to a secure firmware version that addresses the vulnerability.