ZeroHour

CVE-2021-22731

CVSS 3.1
9.8 critical
EPSS
1%p71
Published
()
Modified
Description

Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic user information is known by a remote attacker.

Vendors
schneider-electric
Products
mcsesp083f23g0 firmware, mcsesp083f23g0t firmware, mcsesm043f23f0 firmware, mcsesm053f1cu0 firmware, mcsesm063f2cu0 firmware, mcsesm053f1cs0 firmware, mcsesm063f2cs0 firmware, mcsesm083f23f0 firmware, mcsesm103f2cu0 firmware, mcsesm083f23f0h firmware, mcsesm103f2cu0h firmware, mcsesm103f2cs0h firmware
Weakness
CWE-640
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.