Cross-Site Scripting Vulnerability in APC Network Management Cards
CVE-2021-22810
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 28 January 2022
What is CVE-2021-22810?
A Cross-Site Scripting vulnerability exists in Schneider Electric's APC Network Management Cards that could allow an attacker to execute arbitrary scripts via a malicious URL. Specifically, this flaw can be exploited if a privileged user accesses a specially crafted URL targeting a delete policy file. The vulnerability affects various models of 1-Phase and 3-Phase UPS systems, Power Distribution Units, and environmental monitoring units, particularly those running outdated versions of the NMC firmware. This threat can lead to unauthorized actions and data exposure if not mitigated promptly.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved