PowerLogic EGX100 and PowerLogicEGX300
PowerLogic EGX100 and EGX300 are communication gateway devices used to relay data between power monitoring systems and control networks. Multiple vulnerabilities exist across all versions: improper input validation (CWE-20) combined with authentication bypass (CWE-287) allow an unauthenticated network attacker to execute arbitrary code or trigger denial of service on the device, disrupting its ability to function as a communication bridge in the control system. No patch is available from Schneider Electric; mitigation relies on network isolation and access controls.
- Network access to the EGX100 or EGX300 device (directly or through compromise of the control network)
- No valid credentials required
- Device must be reachable on the network
Patching may require device reboot — plan for process interruption
/api/v1/advisories/c492628d-08d6-4673-bfbc-653e8fe383c0Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.