CVE-2021-22701: CSRF
A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause a user to perform an unintended action on the target device when using the HTTP web interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22701?
CVE-2021-22701 is classified as a medium severity Cross-Site Request Forgery vulnerability.
How do I fix CVE-2021-22701?
To mitigate CVE-2021-22701, it's recommended to update the firmware of affected Schneider Electric PowerLogic devices to the latest versions provided in the security advisory.
What devices are affected by CVE-2021-22701?
CVE-2021-22701 affects Schneider Electric PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000, and PM800 devices.
What kind of attacks can CVE-2021-22701 facilitate?
The vulnerability can allow attackers to perform unintended actions on the device by tricking a logged-in user into issuing requests.
Are there any workarounds for CVE-2021-22701?
While no official workarounds are mentioned for CVE-2021-22701, limiting access to the web interface can reduce exposure until a firmware update is applied.