17% (62) 706 views 5 pages

EcoStruxure Power Monitoring Expert and Power Operation Session Expiration Vulnerability

AI-enhanced description

This document details a security vulnerability (CVE-2023-28003) involving insufficient session expiration in Schneider Electric's EcoStruxure Power Monitoring Expert (PME) and Power Operation (EPO) software, which could allow an attacker to hijack and maintain unauthorized access to a user's session. It provides affected product versions, remediation steps (including specific cumulative updates and hotfixes), and mitigations for unsupported versions to reduce the risk of exploit.

Uploaded by paul.647
Download
/ 5
Loading document…