CVE-2021-22703
—CVSS 3.1
7.5 high
EPSS
<1%p46
Published
()
Modified
Description
A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure of user credentials when a malicious actor intercepts HTTP network traffic between a user and the device.
- Vendors
- schneider-electric
- Products
- powerlogic ion7400 firmware, powerlogic ion7650 firmware, powerlogic ion8600 firmware, powerlogic ion8650 firmware, powerlogic ion8800 firmware, powerlogic ion9000 firmware, powerlogic pm8000 firmware, powerlogic ion8300 firmware, powerlogic ion8400 firmware, powerlogic ion8500 firmware
- Weakness
- CWE-319
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.