8.8
CVE-2016-5809
- EPSS 0.32%
- Published 13.02.2017 21:59:00
- Last modified 20.04.2025 01:37:25
- Source ics-cert@hq.dhs.gov
- Teams watchlist Login
- Open Login
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series. There is no CSRF Token generated to authenticate the user during a session. Successful exploitation of this vulnerability can allow unauthorized configuration changes to be made and saved.
Data is provided by the National Vulnerability Database (NVD)
Schneider-electric ≫ Ion5000 Version-
Schneider-electric ≫ Ion7300 Version-
Schneider-electric ≫ Ion7500 Version-
Schneider-electric ≫ Ion7600 Version-
Schneider-electric ≫ Ion8650 Version-
Schneider-electric ≫ Ion8800 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.32% | 0.52 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.