Lucene search

K
cve[email protected]CVE-2018-7245
HistoryApr 18, 2018 - 8:29 p.m.

CVE-2018-7245

2018-04-1820:29:00
CWE-863
web.nvd.nist.gov
28
cve-2018-7245
improper authorization
vulnerability
schneider electric
66074 mge
network management card transverse
nvd

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

9.1 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

64.7%

An improper authorization vulnerability exists In Schneider Electric’s 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to change UPS control and shutdown parameters or other critical settings without authorization.

Affected configurations

NVD
Node
schneider-electric66074_mge_network_management_card_transverseMatch-
AND
schneider-electricmge_comet_upsMatch-
OR
schneider-electricmge_eps_6000Match-
OR
schneider-electricmge_eps_7000Match-
OR
schneider-electricmge_eps_8000Match-
OR
schneider-electricmge_galaxy_3000Match-
OR
schneider-electricmge_galaxy_4000Match-
OR
schneider-electricmge_galaxy_5000Match-
OR
schneider-electricmge_galaxy_6000Match-
OR
schneider-electricmge_galaxy_9000Match-
OR
schneider-electricmge_galaxy_pwMatch-

CNA Affected

[
  {
    "product": "66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS",
    "vendor": "Schneider Electric SE",
    "versions": [
      {
        "status": "affected",
        "version": "MGE Network Management Card Transverse, part number: SF66074. All card versions affected, when installed in following products: MGE Galaxy 5000, MGE Galaxy 6000, MGE Galaxy 9000, MGE EPS 7000, MGE EPS 8000, MGE EPS 6000, MGE Comet UPS, MGE Galaxy PW, MGE Galaxy 3000, MGE Galaxy 4000"
      }
    ]
  }
]

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

9.1 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

64.7%

Related for CVE-2018-7245