ZeroHour

CVE-2021-22701

CVSS 3.1
4.5 medium
EPSS
<1%p25
Published
()
Modified
Description

A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause a user to perform an unintended action on the target device when using the HTTP web interface.

Vendors
schneider-electric
Products
powerlogic ion7400 firmware, powerlogic ion7650 firmware, powerlogic ion8600 firmware, powerlogic ion8650 firmware, powerlogic ion8800 firmware, powerlogic ion9000 firmware, powerlogic pm8000 firmware, powerlogic ion8300 firmware, powerlogic ion8400 firmware, powerlogic ion8500 firmware
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.