EcoStruxure Power Monitoring Expert and Power Operation Session Expiration Vulnerability
This document details a security vulnerability (CVE-2023-28003) involving insufficient session expiration in Schneider Electric's EcoStruxure Power Monitoring Expert (PME) and Power Operation (EPO) software, which could allow an attacker to hijack and maintain unauthorized access to a user's session. It provides affected product versions, remediation steps (including specific cumulative updates and hotfixes), and mitigations for unsupported versions to reduce the risk of exploit.
Failed to load PDF
Download insteadYou might also like
EcoStruxure Asset Advisor Preventive Service Description
2 pages
Satchwell CXR Room Reset Controller Specification and Installation Guide
11 pages
Twilight Switch for Automatic Roller Blind Control in Air Conditioning Optimization
2 pages
Dependability of MV and HV Protection Devices
16 pages
EasyLogic PM2000 Series Power and Energy Meter Datasheet
8 pages
Classic C2000 Series Horizontal Switched Socket Outlets Ordering Guide
2 pages
Safety Mat System Manual
4 pages
StruxureWare Building Operation Reports Server Manual
4 pages
AP7952 Switched Rack PDU Specifications
2 pages
Eurotherm Data Reviewer Log4shell Mitigation Instructions
4 pages