Lucene search

K
cvelistSchneiderCVELIST:CVE-2023-28003
HistoryApr 18, 2023 - 8:43 p.m.

CVE-2023-28003

2023-04-1820:43:50
CWE-613
schneider
www.cve.org
cwe-613
unauthorized access
hijacked session
pme

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.5%

A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker to
maintain unauthorized access over a hijacked session in PME after the legitimate user has
signed out of their account.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "EcoStruxure Power Monitoring Expert",
    "vendor": "Schneider Electric",
    "versions": [
      {
        "lessThanOrEqual": "PME 2022",
        "status": "affected",
        "version": "All ",
        "versionType": "custom"
      }
    ]
  }
]

6.7 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

46.5%

Related for CVELIST:CVE-2023-28003