CVE-2021-22769
Published on: 06/11/2021 12:00:00 AM UTC
Last Modified on: 09/20/2021 01:51:00 PM UTC
Certain versions of Easergy T300 from Schneider-electric contain the following vulnerability:
A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly restricted.
- CVE-2021-22769 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 4.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | LOW | NONE | NONE |
CVSS2 Score: 4 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
download.schneider-electric.com application/pdf |
![]() | |
download.schneider-electric.com application/pdf |
![]() |
Related QID Numbers
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware | Schneider-electric | Easergy T300 | - | All | All | All |
Operating System | Schneider-electric | Easergy T300 Firmware | All | All | All | All |
Application | Schneider-electric | Enerlinx Comx 510 | All | All | All | All |
- cpe:2.3:h:schneider-electric:easergy_t300:-:*:*:*:*:*:*:*:
- cpe:2.3:o:schneider-electric:easergy_t300_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:a:schneider-electric:enerlin\'x_com\'x_510:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-22769 | 2021-06-11 16:41:53 |