CVE-2021-22702
—CVSS 3.1
7.5 high
EPSS
<1%p45
Published
()
Modified
Description
A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION7700/73xx, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure of user credentials when a malicious actor intercepts Telnet network traffic between a user and the device.
- Vendors
- schneider-electric
- Products
- powerlogic ion7400 firmware, powerlogic ion7650 firmware, powerlogic ion7700 firmware, powerlogic ion7300 firmware, powerlogic ion8600 firmware, powerlogic ion8650 firmware, powerlogic ion8800 firmware, powerlogic ion9000 firmware, powerlogic pm8000 firmware, powerlogic ion8300 firmware, powerlogic ion8400 firmware, powerlogic ion8500 firmware
- Weakness
- CWE-319
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.