CVE-2023-28003: High severity schneider electric ecostruxure power monitoring expert vulnerability
A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain unauthorized access over a hijacked session in PME after the legitimate user has signed out of their account.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-28003?
CVE-2023-28003 is a vulnerability that allows an attacker to maintain unauthorized access over a hijacked session in PME after the legitimate user has signed out of their account.
What is the severity of CVE-2023-28003?
The severity of CVE-2023-28003 is high with a severity value of 8.8.
How does CVE-2023-28003 affect Schneider-electric Ecostruxure Power Monitoring Expert?
CVE-2023-28003 affects Schneider-electric Ecostruxure Power Monitoring Expert by exposing a vulnerability in its session expiration mechanism.
How can I fix CVE-2023-28003?
To fix CVE-2023-28003, it is recommended to apply the necessary security patch or update provided by Schneider-electric.
Where can I find more information about CVE-2023-28003?
You can find more information about CVE-2023-28003 at the following reference link: [link](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-073-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-073-01.pdf)