Lucene search

K
cve[email protected]CVE-2018-7243
HistoryApr 18, 2018 - 8:29 p.m.

CVE-2018-7243

2018-04-1820:29:00
web.nvd.nist.gov
42
cve-2018-7243
authorization bypass
schneider electric
66074 mge
network management card
transverse
vulnerability
nvd

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.0%

An authorization bypass vulnerability exists In Schneider Electric’s 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to get a full access to device, bypassing the authorization system.

Affected configurations

NVD
Node
schneider-electric66074_mge_network_management_card_transverseMatch-
AND
schneider-electricmge_comet_upsMatch-
OR
schneider-electricmge_eps_6000Match-
OR
schneider-electricmge_eps_7000Match-
OR
schneider-electricmge_eps_8000Match-
OR
schneider-electricmge_galaxy_3000Match-
OR
schneider-electricmge_galaxy_4000Match-
OR
schneider-electricmge_galaxy_5000Match-
OR
schneider-electricmge_galaxy_6000Match-
OR
schneider-electricmge_galaxy_9000Match-
OR
schneider-electricmge_galaxy_pwMatch-

CNA Affected

[
  {
    "product": "66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS",
    "vendor": "Schneider Electric SE",
    "versions": [
      {
        "status": "affected",
        "version": "MGE Network Management Card Transverse, part number: SF66074. All card versions affected, when installed in following products: MGE Galaxy 5000, MGE Galaxy 6000, MGE Galaxy 9000, MGE EPS 7000, MGE EPS 8000, MGE EPS 6000, MGE Comet UPS, MGE Galaxy PW, MGE Galaxy 3000, MGE Galaxy 4000"
      }
    ]
  }
]

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

9.3 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

76.0%

Related for CVE-2018-7243