Improper Input Validation in PowerLogic EGX100 and EGX300 by Schneider Electric
CVE-2021-22765
9.8CRITICAL
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 11 June 2021
Summary
A vulnerability in Schneider Electric's PowerLogic EGX100 and EGX300 devices can lead to denial of service or remote code execution due to improper input validation. This issue arises when the device processes specially crafted HTTP packets, making it susceptible to exploitation. Proper security measures should be implemented to mitigate potential risks associated with this vulnerability.
Affected Version(s)
PowerLogic EGX100 ( 3.0.0 and newer) and PowerLogic EGX300 (All ) PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions)
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved