Unrated severityNVD Advisory· Published Dec 17, 2018· Updated Aug 5, 2024
CVE-2018-7797
CVE-2018-7797
Description
A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module, EcoStruxure Power Monitoring Expert (PME) v9.0, EcoStruxure Energy Expert v2.0, and EcoStruxure Power SCADA Operation (PSO) 9.0 Advanced Reports and Dashboards Module which could cause a phishing attack when redirected to a malicious site.
Affected products
4- Range: 1.3, 2.0
- Range: 8.2, 9.0
- Range: 8.2, 9.0
- Schneider Electric SE/Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxureª Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxureª Energy Expert 1.3 (formerly Power Manager), EcoStruxureª Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module, EcoStruxureª Power Monitoring Expert (PME) v9.0, EcoStruxureª Energy Expert v2.0, and EcoStruxureªPower SCADA Operation (PSO) 9.0 Advanced Reports and Dashboards Modulev5Range: EcoStruxureª
Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/106277mitrevdb-entryx_refsource_BID
- www.schneider-electric.com/en/download/document/SEVD-2018-347-01/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.