First published: Tue Apr 18 2023(Updated: )
A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized access over a hijacked session in PME after the legitimate user has signed out of their account.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric EcoStruxure Power Monitoring Expert | <=2022 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28003 is a vulnerability that allows an attacker to maintain unauthorized access over a hijacked session in PME after the legitimate user has signed out of their account.
The severity of CVE-2023-28003 is high with a severity value of 8.8.
CVE-2023-28003 affects Schneider-electric Ecostruxure Power Monitoring Expert by exposing a vulnerability in its session expiration mechanism.
To fix CVE-2023-28003, it is recommended to apply the necessary security patch or update provided by Schneider-electric.
You can find more information about CVE-2023-28003 at the following reference link: [link](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-073-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-073-01.pdf)