Missing Authentication Vulnerability in C-Bus Toolkit by Schneider Electric
CVE-2021-22784

5.7MEDIUM

Key Information:

Vendor
CVE Published:
21 July 2021

Summary

A vulnerability exists in C-Bus Toolkit versions prior to 1.15.8, allowing attackers to exploit missing authentication controls. By crafting a malicious webpage, an attacker can potentially gain unauthorized remote access to the system, compromising its integrity and exposing sensitive data. This highlights the importance of robust authentication measures in critical applications to safeguard against unauthorized access.

Affected Version(s)

C-Bus Toolkit v1.15.8 and prior C-Bus Toolkit v1.15.8 and prior

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.