A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to perform actions via the web interface at a higher privilege level.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Ecostruxure_energy_expert | Schneider-electric | 2.0 (including) | 2.0 (including) |
Ecostruxure_power_monitoring_expert | Schneider-electric | 7.0 (including) | 7.0 (including) |
Ecostruxure_power_monitoring_expert | Schneider-electric | 8.0 (including) | 8.0 (including) |
Ecostruxure_power_monitoring_expert | Schneider-electric | 9.0 (including) | 9.0 (including) |
Power_manager | Schneider-electric | 1.1 (including) | 1.1 (including) |
Power_manager | Schneider-electric | 1.2 (including) | 1.2 (including) |
Power_manager | Schneider-electric | 1.3 (including) | 1.3 (including) |
Powerscada_expert_with_advanced_reporting_and_dashboards | Schneider-electric | 8.0 (including) | 8.0 (including) |
Powerscada_operation_with_advanced_reporting_and_dashboards | Schneider-electric | 9.0 (including) | 9.0 (including) |