Schneider Electric EcoStruxure Power Monitoring Expert
cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:*:*:*:*:*:*:*
- 2023
- 2023 R2
- 2024
- 2024 R2
A vulnerability exists in Schneider Electric's EcoStruxure Power Monitoring Expert (PME) and Power Operation (EPO) products, specifically in multi-tenant deployments. This vulnerability, categorized as CWE-668, exposes TGML diagram resources to the wrong control sphere, allowing other authenticated users inappropriate access to these diagrams. The issue is present in EcoStruxure Power Monitoring Expert versions 2023, 2023 R2, 2024, and 2024 R2, as well as EcoStruxure Power Operation 2022 and 2024 with the Advanced Reporting and Dashboards Module.
Exploitation of this vulnerability could lead to unauthorized access to TGML diagrams by other authenticated users within the same control sphere.
Users can contact Schneider Electric's Customer Care Center to download the hotfixes available for each affected version. For EcoStruxure Power Operation 2022 and 2024 with Advanced Reporting, it's necessary to update EcoStruxure Power Monitoring Expert separately and apply the appropriate hotfix.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.