What's new in Power Monitoring Expert 2024 R3
Power Monitoring Expert 2024 R3 is a major release that introduces a number of new features and improvements. We strongly recommend you upgrade your existing Power Monitoring Expert system to version Power Monitoring Expert 2024 R3.
Highlights of this release - Oct 2025 (PME 2024 R3)
-
PME can now scale to support Extra Large (XL) systems for historical data logging only. Refer to the Deployment Guide for Extra Large (XL) Systems to deploy PME with XL system. Real-time data logging is not supported in the XL System architecture.
NOTE: Before you deploy PME with XL system, you must follow the Planning Checklist for XL System to understand the deployment considerations and limitations for XL System.
- PME now supports Windows Server 2025 Standard and Data center editions for the Application Server.
- PME License grace period increased from 21 days to 90 days for all licenses.
- LTSC (Long-Term Servicing Channel) support for Windows 10 IoT Enterprise LTSC, Windows 11 IoT Enterprise LTSC, Windows 10 Enterprise LTSC, Windows 11 Enterprise LTSC, and Windows Server 2016, 2019 and 2022 (Standard and Data center).
- Cybersecurity and quality hardening fixes.
Details of this release
NOTE: The following is a selected list of changes for this release, it is not a comprehensive list.
Web Applications
| Item | Details |
|---|---|
| Single Sign On enhancements |
You can now configure SSO user group privileges in the PME Web Application under the User Manager > User Groups section. NOTE: An SSO user group appears only when one user in the SSO User Groups logs into PME for the first time. |
Reports and Gadgets
| Item | Details |
|---|---|
| Improved reports |
Updates to the Generator Test EPSS Report provide enhanced features for reporting with ASCO Automatic Transfer Switches, such as calculated transfer time for ASCO ATS evaluation. General report improvements such as updated Generator Summary, enhanced report structure, and new glossary page also included. |
Operating Environment
| Item | Details |
|---|---|
| New Windows Server |
2025 Standard and Data center editions |
| Operating System |
Windows 10 IoT Enterprise LTSC
|
For the complete list of supported operating systems and SQL Server versions, see the IT requirements Operating Environment chapter in the PME system guide.
Cybersecurity improvements
Cybersecurity vulnerabilities related to the Web Applications have been addressed in this release. It is important that you upgrade to this version of software as soon as possible.
| Vulnerability | Details |
|---|---|
| Out-of-Date and Vulnerable Third-Party Dependencies | Telerik.Web.UI.dll CVE-2025-3600, DOMPurify 2.3.4, deprecated_DateTimeHelper.js, requirejs 2.1.11 (CVE 6.9), openssl 3.4.0 (CVE 6.3)canvg vulnerabilities, underscore 1.9.1 (CVE 5.5), jquery.color v2.1.2, jqGrid v4.4.4, modernizr v2.8.3, NCalc.dll v1.3.8, NetMQ.dll v3.3.3.4, PubSubJS, Quartz.dll v2.3.3.0, SnmpSharpNet.dll v0.9.5 and Unity Container v5.11.1 - These components are upgraded to meet the latest cybersecurity regulatory versions. |
|
ZDI-CAN-26273 - GetTgmlContent Directory Traversal |
Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability exists that could cause unauthorized access to sensitive files when an authenticated attackers use a crafted path input that is processed by the system. The issue was resolved by adding stricter validation for file extension types. |
|
ZDI-CAN-26274 - HttpPostedFile Directory Traversal |
Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) vulnerability exists that could cause remote code execution when an authenticated attacker with admin privileges uploads a malicious file over HTTP which then gets executed. The issue was resolved by adding extra sanitization and restricting the unauthorized access to the endpoint. |
|
ZDI-CAN-26275 -GetFilteredSinkProvider Deserialization |
Vulnerability exists that could cause remote code execution and compromise of system integrity when authenticated users send crafted data to a network-exposed service that performs unsafe deserialization. The issue was resolved by adding dynamic port checks to the remote endpoint, ensuring only trusted endpoints approved by the Supervisor are allowed. |
|
ZDI-CAN-26463-GetPagesAsImages Server-Side Request |
Server - Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker configures the application to access a malicious URL. The issue was resolved by restricting custom URLs to those that match the host name, host IP, or an authorized list. All other URLs are excluded from reports. |
|
ZDI-CAN-26464: Server-Side Request Forgery Information |
Server - Side Request Forgery (SSRF) - vulnerability exists that could cause unauthorized access to sensitive data when an attacker sends a specially crafted document to a vulnerable endpoint. The issue was resolved by validating input and throwing exceptions when external URLs or paths are passed in variables, preventing unauthorized data extraction. |
| Missing Binary Security Protections |
|
Fixed Issues
Following is a list of fixed issues for this release:
- Fixed an issue where Windows users could not log in to PME unless their access level was set to Supervisor.
- Fixed a logging issue where EWS data with decimal values was not recorded when the user language was set to a non-English locale.
- Fixed a nuisance alarm related to Micrologic X (LSI) protection settings that occurred when PME services or the IFE module restarted.
- Fixed an issue where EWS real-time data failed to load in the Web App after re-login, resulting in an Unauthorized error.
- Fixed an issue where deleting a user group in User Manager showed an error message, even though the group was deleted.
- Fixed a crash in ION Appmod core services caused by a case mismatch between serviceName and serverName. The comparison is now case-insensitive.
- Fixed an issue of device import failure in Device Manager when the device name contains spaces.
- Fixed a translation issue where the Circuit Breaker Closed string was not displayed in Chinese on the Alarms page when the locale was set to zh-CHS.
- Fixed an OPC site configuration issue when using a domain user.
- Fixed an issue where the ETL Load task overwrote existing values even when the Allow existing values to be overwritten was disabled.
- Fixed an issue of inconsistent behavior of pop-up snippets in the PME Web Application.
- Fixed a login issue for users from trusted Active Directory domains(despite being part of valid Windows groups) due to case mismatch. The comparison is now case-insensitive.
- Fixed inconsistent delivery of SMS alarm notifications sent via Twilio to users in the notification group.
- Fixed an issue of alarm processing delays caused by SQL execution timeouts and deadlocks.
- Added a feature enhancement in SSO where user can provide any user group names.
- Fixed a rendering issue in Sankey diagrams that caused a Maximum call stack size exceeded error using hierarchies with custom templates.
- Fixed an issue out-of-memory exceptions in ION RealTime Services during prolonged use of Vista and WebReach.
- Fixed excessive RAM usage in the ION XML Subscription service when multiple diagram pages were open.
- Fixed an issue for intermittent PME license check failures on Linux-based KVM virtual hosts due to missing hostId.
- Fixed incorrect timestamps in CSV exports from the Trend Chart gadget.
- Fixed an issue where breaker devices were missing in the Breaker Performance tool when more than 50 breakers were added.
- Fixed a database issue where new records were appended instead of overwriting existing ones in the IEC_2_4_StandardLimits tables after reconfiguring.
- Fixed an issue where Create model report failed to generate when Virtual meter is selected as dependent variable.
- Fixed an issue where Indicates tolerance was exceeded legend is misplaced in the report when user selects more than 8 sources by merging the legend to the table.
- Fixed an issue where dashboards could not be saved if the Web Viewer gadget source URL contained the [@SERVER] placeholder.
- Fixed an issue where Create Model Report generates with error when custom measurements are selected.
- Fixed an issue in Dashboards where Energy Equivalency gadget failed to save when a low multiplier value was set.
- Fixed a resizing issue where dashboard gadgets appeared shrunk after resizing the browser window.
- Fixed an issue where Control Action requests from Web Diagrams did not work for advanced security devices.
- Fixed a reporting issue in the Energy Usage by Shift report when Custom Day was enabled.
- Added SSO to support assigning users to specific groups and granting group-based privileges independently of the default Global group.
- Replaced nltest.exe with LDAPS for retrieving trusted Windows domains.
- Fixed an issue by improving the Hierarchy Manager layout to support scrolling and prevent overflow when hierarchies are expanded.
- Fixed an issue by setting the computer name to first option as default.
- Fixed an issue where the Source Measurement list failed to load in Diagrams, Dashboards, Trends, and Reports by checking all available data sources and matching them with signature drivers.
Known Issues
Following is a list of known issues for this release:
- Dashboard Report shows Navigation to the webpage was canceled message in the report. This may be due to issues with WebImageCapture.exe.
- Reports-Date Format misinterpretation in Fixed Date for dd/MM/yyyy.
- The PUE Summary Report shows an incorrect date when subscribed.
- Dashboards may show errors after upgrading from PME 2021 to PME 2024.
- Reports may display extra characters when both Name and Description fields are selected.
-
After upgrading, the files located in the source folder
Config\Translatorfor custom drivers are not automatically copied to the target folder Config\translator. Manually copy the required files from the source path (..\Schneider Electric\Power Monitoring Expert\CMtool_Archive\config\translators) to the targetConfig\translatorsfolder. To apply the new translator files for custom devices, update the corresponding Collector files in the Multiserver Hub Tool.
Performance
| Item | Details |
|---|---|
| Database Optimization | Modification in the database insertion algorithm helps in faster and more efficient data insertion to the SQL DB. |
What's new in Power Monitoring Expert 2024
Power Monitoring Expert2024 is a major release that introduces a number of new features and improvements. We strongly recommend you upgrade your existing Power Monitoring Expert system to version Power Monitoring Expert2024.
Highlights of this release - Oct 2024 (PME 2024)
- Single Sign On to all PME applications via SAMLv2 compliant Identity Provider (IdP).
- Encrypt data in transit with TLS 1.3.
- Integrate with systems via OPC UA server and client.
- Power event analysis with 3rd party devices via COMTRADE.
- Perform and manage EPSS testing with ASCO devices.
- Simplified ASCO Integration with ASCO Gateway Service.
- Native connectivity to ASCO 7000 devices using the ASCO Automatic Transfer Switch Configuration Tool.
- Analyze utility reliability with SAIDI and SAIFI indexes.
- Visualize disturbance direction (DDD) with TGML .
- Perform control operation via TGML.
Details of this release
NOTE: The following is a selected list of changes for this release, it is not a comprehensive list.
Web Applications
| Item | Details |
|---|---|
| Single Sign On with SAMLv2 and MFA | You can add PME in a SAMLv2 compliant Identity Provider (IdP). When a user logs onto the IdP and is authenticated by the IdP, they can perform Single Sign On to all PME web and Windows applications. Multi Factor Authentication can be part of authentication process in the IdP. |
| Interactive TGML Write Operation |
You can create TGML graphics that can accept your input values to the devices. You can also add animations to the component. |
| OPC UA server and client | You can use PME as a OPC UA server which can export device real-time data to another application/ another system. You can use PME as a OPC UA Client to import device real-time data into PME from another application. |
| Power event analysis with 3rd party devices via COMTRADE | You can import COMTRADE waveforms from the 3rd party devices into PME system and analyze the PQ data. |
| Enhanced versions of the Generator Performance Configuration Tool and Generator Test EPSS Report that provide better support of ASCO Automatic Transfer Switches | Updates to the Generator Test EPSS Report provide enhanced features for reporting with ASCO Automatic Transfer Switches, such as calculated transfer time for ASCO ATS evaluation. General report improvements such as updated Generator Summary, enhanced report structure, and new glossary page also included. |
| Native connectivity to ASCO 7000 devices | A new architecture consisting of the ASCO Gateway Service and the ASCO Automatic Transfer Switch Configuration Tool is embedded in PME 2024, allowing direct connection to ASCO 7000 ATS and eliminating the need for an ASCO CPMA gateway in the system architecture. |
| Updated device drivers (ASCO 7000/4000) | ASCO 7000/4000 driver is enhanced to support additional ATS statuses, settings, and alarms. |
| Graphic Editor enhancements |
|
| TLS 1.3 support | Encrypt data in transit with TLS 1.3. TLS 1.3 supports stronger Cipher suites and faster handshake. |
| TGML Enhancements |
|
Reports and Gadgets
| Item | Details |
|---|---|
| New reports |
SAIDI and SAIFI |
| Improved reports |
Generator Test EPSS Report |
Operating Environment
| Item | Details |
|---|---|
| New SQL Server version support |
PME supports SQL Server 2022 Standard/Enterprise/Business Intelligence. SQL Server 2022 Express is included with PME2024 |
For the complete list of supported operating systems and SQL Server versions, see the IT Requirements Operating Environment chapter in this guide.
Devices
| Item | Details |
|---|---|
| New device type support |
The following device types are now supported in PME2024:
|
| Updated device type support |
The following device types are updated in PME2024:
|
Cybersecurity improvements
Cybersecurity vulnerabilities related to the Web Applications have been addressed in this release. It is important that you upgrade to this version of software as soon as possible.
| Item | Details |
|---|---|
| SysLog support over TLS | Syslog is a standardized message logging protocol supported for transmitting data. Messages configured in PME will be sent to configured Syslog server. |
| Real-time Endpoints support |
Trust/Reject the Real-time Endpoints/applications that tries to read real-time data from PME. |
Performance
| Item | Details |
|---|---|
| Quality improvements |
PME2024 includes a wide range of quality improvements:
|