The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric PowerLogic ION8650 All Versions
- Schneider Electric PowerLogic ION8800 All Versions
- Summary
- A CWE-79 Improper Neutralization of Input During Web Page Generation vulnerability exists that could cause compromise of a user’s browser when an attacker with admin privileges has modified system values.
- Remediation
- CVE-2023-5985 Ensure that the device firmware is up to date, and the web service is disabled if not required for operation.
