← Back to CVEs
CVE-2021-22721
MEDIUM5.3
Description
A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to get limited knowledge of javascript code when crafted malicious parameters are submitted to the charging station web server.
CVE Details
CVSS v3.1 Score5.3
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
Published7/21/2021
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
schneider-electric:evlink_city_evc1s22p4schneider-electric:evlink_city_evc1s22p4_firmwareschneider-electric:evlink_city_evc1s7p4schneider-electric:evlink_city_evc1s7p4_firmwareschneider-electric:evlink_parking_ev.2schneider-electric:evlink_parking_ev.2_firmwareschneider-electric:evlink_parking_evf2schneider-electric:evlink_parking_evf2_firmwareschneider-electric:evlink_parking_evw2schneider-electric:evlink_parking_evw2_firmwareschneider-electric:evlink_smart_wallbox_evb1aschneider-electric:evlink_smart_wallbox_evb1a_firmware
Weaknesses (CWE)
CWE-200
References
http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-06(cybersecurity@se.com)
http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-06(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.