Description
A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure of user credentials when a malicious actor intercepts HTTP network traffic between a user and the device.
Published: 2021-02-19
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-9838 A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure of user credentials when a malicious actor intercepts HTTP network traffic between a user and the device.
History

No history.

Subscriptions

Schneider-electric Powerlogic Ion7400 Powerlogic Ion7400 Firmware Powerlogic Ion7650 Powerlogic Ion7650 Firmware Powerlogic Ion8300 Powerlogic Ion8300 Firmware Powerlogic Ion8400 Powerlogic Ion8400 Firmware Powerlogic Ion8500 Powerlogic Ion8500 Firmware Powerlogic Ion8600 Powerlogic Ion8600 Firmware Powerlogic Ion8650 Powerlogic Ion8650 Firmware Powerlogic Ion8800 Powerlogic Ion8800 Firmware Powerlogic Ion9000 Powerlogic Ion9000 Firmware Powerlogic Pm8000 Powerlogic Pm8000 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2024-08-03T18:51:07.062Z

Reserved: 2021-01-06T00:00:00.000Z

Link: CVE-2021-22703

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-02-19T16:15:13.157

Modified: 2024-11-21T05:50:29.640

Link: CVE-2021-22703

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses