The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxure Power Monitoring Exper <=2020
- Schneider Electric EcoStruxure Power Monitoring Exper <=9.0
- Summary
- A Denial of Service vulnerability exists in FlexNet Publisher's lmadmin tool, when doing a crafted POST request on lmadmin using web-based tool. This tool is deployed with PME and an attacker leveraging this vulnerability may be able, with a sustained attack, to stop PME from operating
- Remediation
- Remediation Steps: 1. Install Version 2020 CU3 of EcoStruxure Power Monitoring Expert which includes a fix for CVE-2022-22726, CVE-2022- 22727, and CVE-2022-22804. 2. Install Floating License Manager 2.7 after PME 2020 CU3 installation to address CVE-2019-8963. Both updates can be downloaded here: https://schneiderelectric.app.box.com/folder/152201039971?s=dwbjm0bp3850ek95zyinv6g7nqjj86fm
