The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric EcoStruxure™ Power Monitoring Expert (PME) version 2021 CU1 and prior
- Schneider Electric EcoStruxure™ Power Monitoring Expert (PME) 2020 version 2020 CU2 and prior
- Schneider Electric Advanced Reporting and Dashboards Module for EcoStruxure™ Power Operation version 2021 CU1 and prior
- Schneider Electric Advanced Reporting and Dashboards Module for EcoStruxure™ Power SCADA Operation (PSO) 2020 or 2020 R2 Note 1: Power SCADA Operation and Power Operation without the Advanced Reporting and Dashboards Module are not affected. Note 2: Advanced Reporting and Dashboards Module is equivalent to EcoStruxure™ Power Monitoring Expert. version 2020 CU2 and prior
- Summary
- A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed.
- Remediation
- Version 2021 CU2 of EcoStruxure™ Power Monitoring Expert (PME) includes a fix for these vulnerabilities and is available for download here: https://ecoxpert.se.com/software-center/power-monitoring-expert/power-monitoring-expert-2021
