PatchSiren cyber security CVE debrief
CVE-2021-22764 Schneider Electric CVE debrief
A CWE-287 Improper Authentication vulnerability in Schneider Electric PowerLogic PM55xx series power meters allows unauthenticated attackers to disrupt Modbus TCP connectivity by sending specially crafted HTTP requests. The vulnerability affects PM5560, PM5561, PM5562, and PM5563 models with specific firmware versions, plus the end-of-service PM8ECC. Vendor fixes were released between 2021 and 2024, with the most recent remediation for PM5562 becoming available in November 2024.
- Vendor
- Schneider Electric
- Product
- PowerLogic PM5560 (versions prior to v2.7.8)
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2021-06-08
- Original CVE updated
- 2024-11-12
- Advisory published
- 2021-06-08
- Advisory updated
- 2024-11-12
Who should care
Organizations operating Schneider Electric PowerLogic PM55xx series power meters in industrial environments, particularly those with exposed or poorly segmented network connectivity. Critical infrastructure operators, facility management teams, and OT security practitioners should prioritize assessment and remediation.
Technical summary
The vulnerability stems from improper authentication mechanisms in the HTTP service of affected PowerLogic power meters. An attacker can send a specially crafted HTTP request without authentication, which subsequently causes loss of Modbus TCP protocol connectivity to the device. This represents a denial-of-service condition affecting industrial monitoring and control capabilities. The attack requires network access to the device but no user interaction or privileges.
Defensive priority
medium
Recommended defensive actions
- Apply vendor firmware updates: PM5560 and PM5563 to version 2.8.3 or later; PM5561 to version 10.7.3 or later; PM5562 to version 4.3.5 or later
- If immediate patching is not feasible, block HTTP access to affected devices at the firewall level
- Consider disabling HTTP web services on affected devices where functionality permits
- For PM8ECC devices (end-of-service), implement firewall rules to block HTTP access after commissioning is complete
- Apply defense-in-depth practices for industrial control systems per CISA guidance
- Monitor network traffic for anomalous HTTP requests targeting PowerLogic devices
Evidence notes
CISA CSAF advisory ICSA-24-331-01 documents this vulnerability with vendor confirmation from Schneider Electric. The advisory was originally published June 8, 2021, and updated November 12, 2024, to note remediation availability for PM5562. CVSS 3.1 score of 5.3 (MEDIUM) reflects network-based attack vector with low attack complexity, no privileges required, and availability impact only.
Sources and references
Verified primary and authoritative sources
-
CVE-2021-22764 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2021-22764
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2021-22764 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2021-22764
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-331-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.se.com/us/en/download/document/7EN52-0390/
Reference
-
Source reference
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2021/icsa-24-331-01.json
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-331-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.