Lucene search

K
cve[email protected]CVE-2018-7797
HistoryDec 17, 2018 - 10:29 p.m.

CVE-2018-7797

2018-12-1722:29:00
CWE-601
web.nvd.nist.gov
24
cve-2018-7797
url redirection
power monitoring expert
energy expert
ecostruxure
pme
pso
phishing

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

6.1 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.0%

A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module, EcoStruxure Power Monitoring Expert (PME) v9.0, EcoStruxure Energy Expert v2.0, and EcoStruxure Power SCADA Operation (PSO) 9.0 Advanced Reports and Dashboards Module which could cause a phishing attack when redirected to a malicious site.

Affected configurations

NVD
Node
schneider-electricecostruxure_energy_expertMatch1.3
OR
schneider-electricecostruxure_energy_expertMatch2.0
OR
schneider-electricecostruxure_power_monitoring_expertMatch8.2
OR
schneider-electricecostruxure_power_monitoring_expertMatch9.0
OR
schneider-electricecostruxure_power_scada_operationMatch8.2
OR
schneider-electricecostruxure_power_scada_operationMatch9.0

CNA Affected

[
  {
    "product": "Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxureª Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxureª Energy Expert 1.3 (formerly Power Manager), EcoStruxureª Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module, EcoStruxureª Power Monitoring Expert (PME) v9.0, EcoStruxureª Energy Expert v2.0, and EcoStruxureªPower SCADA Operation (PSO) 9.0 Advanced Reports and Dashboards Module",
    "vendor": "Schneider Electric SE",
    "versions": [
      {
        "status": "affected",
        "version": "EcoStruxure&#xaa"
      },
      {
        "status": "affected",
        "version": "Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure&#xaa"
      },
      {
        "status": "affected",
        "version": "Energy Expert 1.3 (formerly Power Manager), EcoStruxure&#xaa"
      },
      {
        "status": "affected",
        "version": "Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module, EcoStruxure&#xaa"
      },
      {
        "status": "affected",
        "version": "Power Monitoring Expert (PME) v9.0, EcoStruxure&#xaa"
      },
      {
        "status": "affected",
        "version": "Energy Expert v2.0, and EcoStruxure&#xaa"
      },
      {
        "status": "affected",
        "version": "Power SCADA Operation (PSO) 9.0 Advanced Reports and Dashboards Module"
      }
    ]
  }
]

5.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

6.1 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

6.1 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

39.0%

Related for CVE-2018-7797