CVE-2016-5809
Severity CVSS v4.0:
Pending analysis
Type:
CWE-352
Cross-Site Request Forgery (CSRF)
Publication date:
13/02/2017
Last modified:
20/04/2025
Description
An issue was discovered on Schneider Electric IONXXXX series power meters ION73XX series, ION75XX series, ION76XX series, ION8650 series, ION8800 series, and PM5XXX series. There is no CSRF Token generated to authenticate the user during a session. Successful exploitation of this vulnerability can allow unauthorized configuration changes to be made and saved.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:h:schneider-electric:ion5000:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:schneider-electric:ion7300:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:schneider-electric:ion7500:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:schneider-electric:ion7600:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:schneider-electric:ion8650:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:schneider-electric:ion8800:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



