Improper Input Validation in PowerLogic EGX100 and EGX300 by Schneider Electric
CVE-2021-22767
9.8CRITICAL
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 11 June 2021
What is CVE-2021-22767?
An improper input validation vulnerability in Schneider Electric's PowerLogic EGX100 and EGX300 may lead to severe consequences, including potential denial of service or remote code execution. Specifically, the flaw arises due to the handling of specially crafted HTTP packets, which can be exploited to manipulate the system's response. Users of affected versions should implement recommended security measures to mitigate risks.
Affected Version(s)
PowerLogic EGX100 ( 3.0.0 and newer) and PowerLogic EGX300 (All ) PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions)