An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to change UPS control and shutdown parameters or other critical settings without authorization.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Schneider-electric
Subscribe
|
66074 Mge Network Management Card Transverse
Subscribe
Mge Comet Ups
Subscribe
Mge Eps 6000
Subscribe
Mge Eps 7000
Subscribe
Mge Eps 8000
Subscribe
Mge Galaxy 3000
Subscribe
Mge Galaxy 4000
Subscribe
Mge Galaxy 5000
Subscribe
Mge Galaxy 6000
Subscribe
Mge Galaxy 9000
Subscribe
Mge Galaxy Pw
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-18984 | An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to change UPS control and shutdown parameters or other critical settings without authorization. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2024-08-05T06:24:11.357Z
Reserved: 2018-02-19T00:00:00
Link: CVE-2018-7245
No data.
Status : Modified
Published: 2018-04-18T20:29:00.513
Modified: 2024-11-21T04:11:52.157
Link: CVE-2018-7245
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD