Improper Input Validation Vulnerability in PowerLogic EGX100 and EGX300 Products by Schneider Electric
CVE-2021-22766
7.5HIGH
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 11 June 2021
Summary
An improper input validation vulnerability has been identified in the PowerLogic EGX100 and EGX300 products by Schneider Electric. This flaw allows an attacker to craft a specially designed HTTP packet that can lead to a denial of service condition in the affected devices. Users of these products should be aware of this vulnerability and take necessary precautions to secure their systems against potential exploitation.
Affected Version(s)
PowerLogic EGX100 ( 3.0.0 and newer) and PowerLogic EGX300 (All ) PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions)
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved