ZeroHour

CVE-2021-22799

CVSS 3.1
3.8 low
EPSS
<1%p15
Published
()
Modified
Description

A CWE-331: Insufficient Entropy vulnerability exists that could cause unintended connection from an internal network to an external network when an attacker manages to decrypt the SESU proxy password from the registry. Affected Product: Schneider Electric Software Update, V2.3.0 through V2.5.1

Vendors
schneider-electric
Products
software update
Weakness
CWE-331
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.