Schneider Electric EcoStruxure Power Monitoring Expert
cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:*:*:*:*:*:*:*
- 2022
- 2023
- 2024
- 2024 R2
A server-side request forgery (SSRF) vulnerability has been identified in Schneider Electric's EcoStruxure Power Monitoring Expert (PME) 2022, 2023, 2024, and 2024 R2 versions, as well as in EcoStruxure Power Operation (EPO) 2022 and 2024 with the Advanced Reporting and Dashboards Module. This vulnerability could allow unauthorized access to sensitive data by exploiting a vulnerable endpoint with a specially crafted document.
Exploitation of this vulnerability could lead to unauthorized access to sensitive data.
Users can upgrade to EcoStruxure Power Monitoring Expert (PME) 2024 R2 or apply Hotfix_269509_Release_13.1 and Hotfix_269476_Release_13.1 for EcoStruxure Power Operation (EPO) 2024 with the Advanced Reporting and Dashboards Module. For EcoStruxure Power Monitoring Expert (PME) 2022, which is no longer supported, customers should apply recommended cybersecurity hardening guidelines and consider upgrading to a supported version.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.