CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Schneider Electric PowerLogic P7

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 275

As cited

Copy frozen at (site build).

vulnerabilities

Schneider Electric PowerLogic P7

Schneider Electric disclosed three vulnerabilities in its PowerLogic P7 protection and control platform affecting versions 0.2.003.001.000 and prior. The issues include a NULL pointer dereference causing denial of service, an OS command injection allowing unauthorized privileged command execution, and a reachable assertion enabling authenticated denial of service attacks. Affected users should upgrade to version V02.004.001 or apply network access restrictions and monitoring controls.

Why it matters: OS command injection in PowerLogic P7 poses immediate risk to critical infrastructure operators; prioritize patching or implement network segmentation on ports 8080 and 3702 to prevent unauthorized system control or operational disruption.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Schneider Electric PowerLogic P7

Schneider Electric disclosed three vulnerabilities in its PowerLogic P7 protection and control platform affecting versions 0.2.003.001.000 and prior. The issues include a NULL pointer dereference causing denial of service, an OS command injection allowing unauthorized privileged command execution, and a reachable assertion enabling authenticated denial of service attacks. Affected users should upgrade to version V02.004.001 or apply network access restrictions and monitoring controls.

Why it matters: OS command injection in PowerLogic P7 poses immediate risk to critical infrastructure operators; prioritize patching or implement network segmentation on ports 8080 and 3702 to prevent unauthorized system control or operational disruption.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary