ZeroHour

CVE-2021-22763

CVSS 3.1
9.8 critical
EPSS
2%p78
Published
()
Modified
Description

A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists in PowerLogic PM55xx, PowerLogic PM8ECC, PowerLogic EGX100 and PowerLogic EGX300 (see security notification for version infromation) that could allow an attacker administrator level access to a device.

Vendors
schneider-electric
Products
powerlogic pm5560 firmware, powerlogic pm5561 firmware, powerlogic pm5562 firmware, powerlogic pm5563 firmware, powerlogic pm8ecc firmware
Weakness
CWE-640
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.