TROYANOSYVIRUS
Retour aux CVEs

CVE-2021-22706

MEDIUM
6.1

Description

A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to impersonate the user who manages the charging station or carry out actions on their behalf when crafted malicious parameters are submitted to the charging station web server.

Details CVE

Score CVSS v3.16.1
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurREQUIRED
Publie7/21/2021
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0

Produits affectes

schneider-electric:evlink_city_evc1s22p4schneider-electric:evlink_city_evc1s22p4_firmwareschneider-electric:evlink_city_evc1s7p4schneider-electric:evlink_city_evc1s7p4_firmwareschneider-electric:evlink_parking_ev.2schneider-electric:evlink_parking_ev.2_firmwareschneider-electric:evlink_parking_evf2schneider-electric:evlink_parking_evf2_firmwareschneider-electric:evlink_parking_evw2schneider-electric:evlink_parking_evw2_firmwareschneider-electric:evlink_smart_wallbox_evb1aschneider-electric:evlink_smart_wallbox_evb1a_firmware

Faiblesses (CWE)

CWE-79

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.