EcoStruxure Power Monitoring Expert and Power Operation Session Expiration Vulnerability
This document details a security vulnerability (CVE-2023-28003) involving insufficient session expiration in Schneider Electric's EcoStruxure Power Monitoring Expert (PME) and Power Operation (EPO) software, which could allow an attacker to hijack and maintain unauthorized access to a user's session. It provides affected product versions, remediation steps (including specific cumulative updates and hotfixes), and mitigations for unsupported versions to reduce the risk of exploit.
Failed to load PDF
Download insteadYou might also like
Sealed Lead Acid Battery Pack Product Safety Datasheet
14 pages
SLO320 Outdoor Light Transmitter Specification Sheet
3 pages
SXWS Living Space Sensor Specification Sheet
10 pages
Geo SCADA Expert 2019 Release Notes
47 pages
Fidelio Front Office PIU Protocol Interface Unit Manual
4 pages
Satchwell RB2 Relay Unit Installation and Specification Guide
2 pages
Electrical Ageing of High-Voltage Composite Insulation: An Industrial Perspective
7 pages
Automated Fault Detection and Diagnostics Guide Specification
7 pages
SP-MI16 Security Purpose Mini Input Expansion Module Manual
4 pages
H723LC-S6 Current Transducer Installation Guide
3 pages