CVE Feed

    Dashboard / CVE / CVE-2021-22764

    CVE-2021-22764

    A CWE-287: Improper Authentication vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could cause loss of connectivity to the device via Modbus TCP protocol when an attacker sends a specially crafted HTTP request.

    Published:Jun 11, 2021
    Last Modified:May 29, 2026
    EPS:Jun 11, 2021
    EPSS Score:0.00248
    CVSS Score:5.3

    Affected Products

    Vendor
    Schneider-electric
    Product
    Powerlogic Pm5560
    Vendor
    Schneider-electric
    Product
    Powerlogic Pm5560 Firmware
    Vendor
    Schneider-electric
    Product
    Powerlogic Pm5561
    Vendor
    Schneider-electric
    Product
    Powerlogic Pm5561 Firmware
    Vendor
    Schneider-electric
    Product
    Powerlogic Pm5562
    Vendor
    Schneider-electric
    Product
    Powerlogic Pm5562 Firmware
    Vendor
    Schneider-electric
    Product
    Powerlogic Pm5563
    Vendor
    Schneider-electric
    Product
    Powerlogic Pm5563 Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High