logo

Team82 Uncovers Vulnerabilities in Schneider Electric Smart Meters

ID: 939cadbb-2c54-5608-8c0b-8830264328d0

STIX ID: report--939cadbb-2c54-5608-8c0b-8830264328d0

Feed Name: Claroty Team82

Threat Score
78/100

Date Published: 2023-09-07

Date Updated: 2026-04-17

Author: Tal Keren

...
...

Team82/Claroty discovered two pre-authentication integer-overflow vulnerabilities in Schneider Electric PowerLogic ION smart meters that could, depending on device generation and architecture, enable remote code execution or force reboots (denial-of-service). The flaws stem from improper buffer and parser handling of a proprietary ION protocol over TCP port 7700; affected models include multiple ION and PM lines with CVSS ratings up to 9.8. Schneider Electric released advisories and patches (various V3/V4 updates) and urged users to update or upgrade unsupported devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.