|
195361
|
8.8 |
HIGH
Network
|
schneider-electric
|
ecostruxure_power_monitoring_expert
|
A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22827.…
|
CWE-20
Improper Input Validation
|
CVE-2021-22826
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195362
|
5.5 |
MEDIUM
Local
|
schneider-electric
|
guicon
|
A CWE-125:Out-of-Bounds Read vulnerability exists that could cause unintended data disclosure when a malicious *.gd1 configuration file is loaded into the GUIcon tool. Affected Product: Eurotherm by …
|
CWE-125
Out-of-bounds Read
|
CVE-2021-22809
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195363
|
7.8 |
HIGH
Local
|
schneider-electric
|
guicon
|
A CWE-416: Use After Free vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool. Affected Product: Eurotherm by Schne…
|
CWE-416
Use After Free
|
CVE-2021-22808
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195364
|
8.0 |
HIGH
Network
|
schneider-electric
|
rack_power_distribution_unit_with_network_management_card_2_firmware rack_power_distribution_unit_with_network_management_card_3_firmware
|
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could allow an attacker to access the system with elevated privileges when a privileged account clicks …
|
CWE-200
Information Exposure
|
CVE-2021-22825
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195365
|
6.1 |
MEDIUM
Network
|
schneider-electric
|
evlink_city_evc1s22p4_firmware evlink_city_evc1s7p4_firmware evlink_parking_evw2_firmware evlink_parking_evf2_firmware evlink_parking_evp2pe_firmware evlink_smart_wallbox_evb1a_firmware
|
A CWE-79 Improper Neutralization of Input During Web Page Generation (?Cross-site Scripting?) vulnerability exists that could allow an attacker to impersonate the user who manages the charging statio…
|
CWE-79
Cross-site Scripting
|
CVE-2021-22822
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195366
|
8.6 |
HIGH
Network
|
schneider-electric
|
evlink_city_evc1s22p4_firmware evlink_city_evc1s7p4_firmware evlink_parking_evw2_firmware evlink_parking_evf2_firmware evlink_parking_evp2pe_firmware evlink_smart_wallbox_evb1a_firmware
|
A CWE-918 Server-Side Request Forgery (SSRF) vulnerability exists that could cause the station web server to forward requests to unintended network targets when crafted malicious parameters are submi…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2021-22821
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195367
|
9.8 |
CRITICAL
Network
|
schneider-electric
|
evlink_city_evc1s22p4_firmware evlink_city_evc1s7p4_firmware evlink_parking_evw2_firmware evlink_parking_evf2_firmware evlink_parking_evp2pe_firmware evlink_smart_wallbox_evb1a_firmware
|
A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked session to the charger station web server even after the…
|
CWE-613
Insufficient Session Expiration
|
CVE-2021-22820
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195368
|
4.3 |
MEDIUM
Network
|
schneider-electric
|
evlink_city_evc1s22p4_firmware evlink_city_evc1s7p4_firmware evlink_parking_evw2_firmware evlink_parking_evf2_firmware evlink_parking_evp2pe_firmware evlink_smart_wallbox_evb1a_firmware
|
A CWE-1021 Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause unintended modifications of the product settings or user accounts when deceiving the user to use …
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2021-22819
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195369
|
7.8 |
HIGH
Local
|
schneider-electric
|
guicon
|
A CWE-787: Out-of-bounds Write vulnerability exists that could cause arbitrary code execution when a malicious *.gd1 configuration file is loaded into the GUIcon tool. Affected Product: Eurotherm by …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-22807
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195370
|
3.8 |
LOW
Local
|
schneider-electric
|
software_update
|
A CWE-331: Insufficient Entropy vulnerability exists that could cause unintended connection from an internal network to an external network when an attacker manages to decrypt the SESU proxy password…
|
CWE-331
Insufficient Entropy
|
CVE-2021-22799
|
2024-11-21 14:50 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|