Missing Authentication Vulnerability in C-Bus Toolkit by Schneider Electric
CVE-2021-22784
5.7MEDIUM
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 21 July 2021
Summary
A vulnerability exists in C-Bus Toolkit versions prior to 1.15.8, allowing attackers to exploit missing authentication controls. By crafting a malicious webpage, an attacker can potentially gain unauthorized remote access to the system, compromising its integrity and exposing sensitive data. This highlights the importance of robust authentication measures in critical applications to safeguard against unauthorized access.
Affected Version(s)
C-Bus Toolkit v1.15.8 and prior C-Bus Toolkit v1.15.8 and prior
References
CVSS V3.1
Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved