Improper Input Validation Vulnerability in PowerLogic EGX100 and EGX300 Products by Schneider Electric
CVE-2021-22766

7.5HIGH

Summary

An improper input validation vulnerability has been identified in the PowerLogic EGX100 and EGX300 products by Schneider Electric. This flaw allows an attacker to craft a specially designed HTTP packet that can lead to a denial of service condition in the affected devices. Users of these products should be aware of this vulnerability and take necessary precautions to secure their systems against potential exploitation.

Affected Version(s)

PowerLogic EGX100 ( 3.0.0 and newer) and PowerLogic EGX300 (All ) PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions)

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.