CVE-2021-22714

A CWE-119:Improper restriction of operations within the bounds of a memory buffer vulnerability exists in PowerLogic ION7400, PM8000 and ION9000 (All versions prior to V3.0.0), which could cause the meter to reboot or allow for remote code execution.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:schneider-electric:powerlogic_ion7400_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:powerlogic_ion7400:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:schneider-electric:powerlogic_pm8000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:powerlogic_pm8000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:schneider-electric:powerlogic_ion9000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:powerlogic_ion9000:-:*:*:*:*:*:*:*

History

03 Feb 2022, 16:21

Type Values Removed Values Added
CPE cpe:2.3:o:se:powerlogic_ion9000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:se:powerlogic_ion7400_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:se:powerlogic_pm8000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:powerlogic_pm8000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:powerlogic_ion9000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:schneider-electric:powerlogic_ion7400_firmware:*:*:*:*:*:*:*:*

31 Jan 2022, 19:52

Type Values Removed Values Added
CPE cpe:2.3:h:se:powerlogic_ion9000:-:*:*:*:*:*:*:*
cpe:2.3:h:se:powerlogic_pm8000:-:*:*:*:*:*:*:*
cpe:2.3:h:se:powerlogic_ion7400:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:powerlogic_ion9000:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:powerlogic_ion7400:-:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:powerlogic_pm8000:-:*:*:*:*:*:*:*

27 Aug 2021, 14:48

Type Values Removed Values Added
CPE cpe:2.3:o:se:ion7400_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:se:ion7400:-:*:*:*:*:*:*:*
cpe:2.3:o:se:ion9000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:se:ion9000:-:*:*:*:*:*:*:*
cpe:2.3:o:se:pm8000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:se:pm8000:-:*:*:*:*:*:*:*
cpe:2.3:h:se:powerlogic_ion7400:-:*:*:*:*:*:*:*
cpe:2.3:o:se:powerlogic_ion9000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:se:powerlogic_pm8000:-:*:*:*:*:*:*:*
cpe:2.3:o:se:powerlogic_pm8000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:se:powerlogic_ion9000:-:*:*:*:*:*:*:*
cpe:2.3:o:se:powerlogic_ion7400_firmware:*:*:*:*:*:*:*:*

Information

Published : 2021-03-11 21:15

Updated : 2024-02-04 21:23


NVD link : CVE-2021-22714

Mitre link : CVE-2021-22714

CVE.ORG link : CVE-2021-22714


JSON object : View

Products Affected

schneider-electric

  • powerlogic_ion9000
  • powerlogic_ion9000_firmware
  • powerlogic_ion7400
  • powerlogic_pm8000_firmware
  • powerlogic_pm8000
  • powerlogic_ion7400_firmware
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer