An authorization bypass vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to get a full access to device, bypassing the authorization system.
Existe una vulnerabilidad de omisión de autenticación en 66074 MGE Network Management Card Transverse, de Schneider Electric, instalados en MGE UPS y MGE STS. El servidor web integrado (Port 80/443/TCP) de los dispositivos afectados podría permitir que un atacante remoto obtenga acceso completo al dispositivo omitiendo el sistema de autorización.
AV:N/AC:L/Au:N/C:C/I:C/A:C
| Access Vector | NETWORK |
|---|---|
| Access Complexity | LOW |
| Authentication | NONE |
| Confidentiality Impact | COMPLETE |
| Integrity Impact | COMPLETE |
| Availability Impact | COMPLETE |
| Source | Type | Description |
|---|---|---|
| [email protected] | Primary |
en
NVD-CWE-noinfo
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| schneider-electric | 66074_mge_network_management_card_transverse | - | <built-in method update of dict object at 0x7e60a888c1c0> | Hardware |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:h:schneider-electric:66074_mge_network_management_card_transverse:-:*:*:*:*:*:*:* |
| Vulnerable | CPE |
|---|---|
| No | cpe:2.3:h:schneider-electric:mge_comet_ups:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:schneider-electric:mge_eps_6000:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:schneider-electric:mge_eps_7000:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:schneider-electric:mge_eps_8000:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:schneider-electric:mge_galaxy_3000:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:schneider-electric:mge_galaxy_4000:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:schneider-electric:mge_galaxy_5000:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:schneider-electric:mge_galaxy_6000:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:schneider-electric:mge_galaxy_9000:-:*:*:*:*:*:*:* |
| No | cpe:2.3:h:schneider-electric:mge_galaxy_pw:-:*:*:*:*:*:*:* |