EcoStruxure Power Monitoring Expert and Power Operation Session Expiration Vulnerability
This document details a security vulnerability (CVE-2023-28003) involving insufficient session expiration in Schneider Electric's EcoStruxure Power Monitoring Expert (PME) and Power Operation (EPO) software, which could allow an attacker to hijack and maintain unauthorized access to a user's session. It provides affected product versions, remediation steps (including specific cumulative updates and hotfixes), and mitigations for unsupported versions to reduce the risk of exploit.
Failed to load PDF
Download insteadYou might also like
EcoStruxure Microgrid Advisor Platform Description
2 pages
Argus 360 Motion Detector Lighting Control Solution for Hotel Lobby
2 pages
Symmetra PX 20 kW UPS Certificate of Origin
1 pages
Geo SCADA Expert 2019 Release Notes
53 pages
Vijeo Citect V7.20 What's New
2 pages
GV Air Flow Sensor for VAV Systems Technical Specifications
2 pages
Andover Continuum PS 120/240 AC Power Supply Modules Manual
5 pages
SpaceLogic MP-V BACnet/IP Field Controller Manual
15 pages
U6A4 Lithium-Ion Battery System for UPS Product Specification
45 pages
Andover Continuum Universal Enclosures
5 pages