PatchSiren cyber security CVE debrief
CVE-2024-10497 Schneider Electric CVE debrief
CVE-2024-10497 is a high-severity authorization bypass in Schneider Electric Power Logic. The issue can let an authenticated attacker modify values outside their assigned privileges by sending modified HTTPS requests to the device. Schneider Electric has published a fix for HDPM6000 v0.62.7 in v0.62.11 and newer, and CISA’s advisory also recommends restricting HTTPS access to the local network segment if patching is not immediately possible.
- Vendor
- Schneider Electric
- Product
- PowerLogic HDPM6000
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-01-28
- Original CVE updated
- 2025-01-28
- Advisory published
- 2025-01-28
- Advisory updated
- 2025-01-28
Who should care
OT/ICS administrators, Schneider Electric Power Logic HDPM6000 operators, and security teams responsible for devices that allow HTTPS management access. Systems still on v0.62.7 or with management interfaces exposed beyond tightly controlled network segments deserve immediate attention.
Technical summary
According to the CISA CSAF advisory, CVE-2024-10497 is an authorization bypass through a user-controlled key in Schneider Electric Power Logic HDPM6000 v0.62.7. The attacker must already be authorized, but can send modified HTTPS requests that cause the device to accept changes outside the privileges granted to that user. The published CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating network reachability, low privileges, no user interaction, and high impact to confidentiality, integrity, and availability.
Defensive priority
High. The vulnerability is network-reachable, requires only low privileges, and is rated 8.8 HIGH with high CIA impact. Prioritize patching affected devices and hardening management-plane access.
Recommended defensive actions
- Upgrade Schneider Electric Power Logic HDPM6000 from v0.62.7 to v0.62.11 or newer.
- If you cannot patch immediately, ensure HTTPS access is not available outside the local network segment by applying firewall rules and network access controls.
- Protect the management network segment so only authorized administrative systems can reach the device.
- Account for the reboot requirement during firmware updates: a restart occurs when updating through the web UI, and manual restart is needed when upgrading with HDPM6000 Manager software.
Evidence notes
This debrief is based on the CISA CSAF advisory ICSA-25-028-02 and the referenced Schneider Electric remediation guidance. The supplied advisory data identifies Schneider Electric Power Logic HDPM6000 v0.62.7 as affected and lists v0.62.11 and newer as fixed. The supplied enrichment does not mark this CVE as a KEV item.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-10497 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-10497
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-10497 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-10497
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-028-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-028-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.