CVE-2021-22702: High severity Schneider-electric Powerlogic Ion7400 Firmware vulnerability
A CWE-319: Cleartext transmission of sensitive information vulnerability exists in PowerLogic ION7400, ION7650, ION7700/73xx, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause disclosure of user credentials when a malicious actor intercepts Telnet network traffic between a user and the device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22702?
CVE-2021-22702 is rated as a medium severity vulnerability due to the potential disclosure of sensitive information.
How do I fix CVE-2021-22702?
To remediate CVE-2021-22702, ensure that all affected PowerLogic ION devices are updated to the latest firmware version that addresses this vulnerability.
What systems are affected by CVE-2021-22702?
CVE-2021-22702 affects several PowerLogic ION models, including ION7400, ION7650, ION7700, ION8650, ION8800, ION9000, and PM8000.
What does CVE-2021-22702 expose?
CVE-2021-22702 exposes user credentials by allowing the cleartext transmission of sensitive information over the network.
Is CVE-2021-22702 a new vulnerability?
CVE-2021-22702 was publicly disclosed in 2021, focusing on vulnerabilities present in firmware versions of certain PowerLogic ION products.