CVE-2021-22731
—CVSS 3.1
9.8 critical
EPSS
1%p71
Published
()
Modified
Description
Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic user information is known by a remote attacker.
- Vendors
- schneider-electric
- Products
- mcsesp083f23g0 firmware, mcsesp083f23g0t firmware, mcsesm043f23f0 firmware, mcsesm053f1cu0 firmware, mcsesm063f2cu0 firmware, mcsesm053f1cs0 firmware, mcsesm063f2cs0 firmware, mcsesm083f23f0 firmware, mcsesm103f2cu0 firmware, mcsesm083f23f0h firmware, mcsesm103f2cu0h firmware, mcsesm103f2cs0h firmware
- Weakness
- CWE-640
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.