Improper UI Layer Restriction in Schneider Electric EVlink Products
CVE-2021-22819
4.3MEDIUM
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 28 January 2022
What is CVE-2021-22819?
An improper restriction of rendered UI layers or frames vulnerability exists within Schneider Electric's EVlink products. This flaw can be exploited to manipulate product settings or user accounts by deceiving users into interacting with a web interface that is presented within iframes. This could lead to significant security risks, enabling attackers to make unauthorized changes without the user's knowledge. Users are advised to ensure they update to versions R8 V3.4.0.2 or later to mitigate this risk.