Missing Encryption Vulnerability in Wiser Smart Products by Schneider Electric
CVE-2022-30237
8.2HIGH
Summary
A vulnerability exists in Schneider Electric's Wiser Smart products that could permit unauthorized access to authentication credentials. This security flaw arises due to the absence of robust encryption for sensitive data, which means attackers can potentially recover these credentials when they decode the stored information. Users of affected Wiser Smart versions should review their security protocols to mitigate risks associated with this vulnerability.
Affected Version(s)
Wiser Smart EER21000 < 4.5
Wiser Smart EER21001 < 4.5
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved