CVE-2016-5818
critical
CVSS v3
9.8
CVSS v2
7.5
VIR risk
9.8
Description
An issue was discovered in Schneider Electric PowerLogic PM8ECC device 2.651 and older. Undocumented hard-coded credentials allow access to the device.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: ics-cert@hq.dhs.gov — https://ics-cert.us-cert.gov/advisories/ICSA-16-292-01
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| schneider-electric | powerlogic_pm8ecc_firmware | 2.651 | |
References
CWEs
CWE-798
Verify integrity in audit chain (admin only). AS-IS.