First published: Mon May 22 2023(Updated: )
A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, denial of service, or modification of data if an attacker is able to intercept network traffic.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Powerlogic Ion9000 Firmware | <4.0.0 | |
Schneider-electric Powerlogic Ion9000 | ||
Schneider-electric Powerlogic Ion7400 Firmware | <4.0.0 | |
Schneider-electric Powerlogic Ion7400 | ||
Schneider-electric Powerlogic Pm8000 Firmware | <4.0.0 | |
Schneider-electric Powerlogic Pm8000 | ||
Schneider-electric Powerlogic Ion8650 Firmware | ||
Schneider-electric Powerlogic Ion8650 | ||
Schneider-electric Powerlogic Ion8800 Firmware | ||
Schneider-electric Powerlogic Ion8800 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-46680.
The severity of CVE-2022-46680 is critical.
If CVE-2022-46680 is exploited, it can cause disclosure of sensitive information, denial of service, or modification of data.
The affected software versions are Schneider-electric Powerlogic Ion9000 Firmware up to exclusive version 4.0.0, Schneider-electric Powerlogic Ion7400 Firmware up to exclusive version 4.0.0, Schneider-electric Powerlogic Pm8000 Firmware up to exclusive version 4.0.0, Schneider-electric Powerlogic Ion8650 Firmware, and Schneider-electric Powerlogic Ion8800 Firmware.
To fix CVE-2022-46680, it is recommended to refer to the security notice provided by Schneider Electric for detailed remediation steps.