CVE-2018-7797: Schneider Electric Ecostruxure Energy Expert
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module, EcoStruxure Power Monitoring Expert (PME) v9.0, EcoStruxure Energy Expert v2.0, and EcoStruxure Power SCADA Operation (PSO) 9.0 Advanced Reports and Dashboards Module which could cause a phishing attack when redirected to a malicious site.
Affected products
- Schneider Electric Ecostruxure Energy Expert: version 1.3 only; version 2.0 only
- Schneider Electric Ecostruxure Power Monitoring Expert: version 8.2 only; version 9.0 only
- Schneider Electric Ecostruxure Power Scada Operation: version 8.2 only; version 9.0 only
Published 2018-12-17. Last modified 2026-06-17.