8.8
CVSSv3

CVE-2016-5809

Published: 13/02/2017 Updated: 20/05/2018
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

An issue exists on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series. There is no CSRF Token generated to authenticate the user during a session. Successful exploitation of this vulnerability can allow unauthorized configuration changes to be made and saved.

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric ion5000 -

schneider-electric ion8650 -

schneider-electric ion8800 -

schneider-electric ion7300 -

schneider-electric ion7500 -

schneider-electric ion7600 -

Exploits

# Exploit Title: Powerlogic Schneider Electric IONXXXX Series - Cross-Site Request Forgery # Date: 2018-05-17 # Exploit Author: t4rkd3vilz # Vendor Homepage: wwwschneider-electriccom/ # Version: ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, PM5XXX series # Tested on: All Version # CVE : CVE-2016-5809 # P ...
Powerlogic/Schneider Electric IONXXXX Series suffers from a cross site request forgery vulnerability ...