Improper Input Validation in EcoStruxure Power Monitoring Expert by Schneider Electric
CVE-2021-22826
8.8HIGH
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 28 January 2022
What is CVE-2021-22826?
A vulnerability exists in EcoStruxure Power Monitoring Expert due to improper input validation, allowing an attacker to execute arbitrary code when a user visits a page with a maliciously injected payload. This may compromise the system's integrity and lead to unauthorized access or control. Users are advised to apply updates to mitigate potential risks associated with this flaw.