Cross-Site Scripting Vulnerability in APC Network Management Cards
CVE-2021-22810

6.1MEDIUM

Key Information:

Vendor
CVE Published:
28 January 2022

Summary

A Cross-Site Scripting vulnerability exists in Schneider Electric's APC Network Management Cards that could allow an attacker to execute arbitrary scripts via a malicious URL. Specifically, this flaw can be exploited if a privileged user accesses a specially crafted URL targeting a delete policy file. The vulnerability affects various models of 1-Phase and 3-Phase UPS systems, Power Distribution Units, and environmental monitoring units, particularly those running outdated versions of the NMC firmware. This threat can lead to unauthorized actions and data exposure if not mitigated promptly.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.