CVE-2021-22706: XSS
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to impersonate the user who manages the charging station or carry out actions on their behalf when crafted malicious parameters are submitted to the charging station web server.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-22706.
What is the severity of CVE-2021-22706?
The severity of CVE-2021-22706 is medium with a CVSS score of 6.1.
Which software versions are affected by CVE-2021-22706?
EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1) are affected by CVE-2021-22706.
How can I fix CVE-2021-22706?
To fix CVE-2021-22706, it is recommended to update to version R8 V3.4.0.1 or later for the affected software.
Where can I find more information about CVE-2021-22706?
You can find more information about CVE-2021-22706 at the following link: http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-06.