CVE-2021-22707: Critical severity schneider-electric evc1s22p4 firmware vulnerability
A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to issue unauthorized commands to the charging station web server with administrative privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-22707?
The severity of CVE-2021-22707 is critical with a severity value of 9.8.
Which software versions are affected by CVE-2021-22707?
EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1) are affected by CVE-2021-22707.
What is the CWE ID for CVE-2021-22707?
The CWE ID for CVE-2021-22707 is CWE-798.
How can I fix CVE-2021-22707?
To fix CVE-2021-22707, update to version R8 V3.4.0.1 or later for EVlink City, EVlink Parking, and EVlink Smart Wallbox.
Where can I find more information about CVE-2021-22707?
More information about CVE-2021-22707 can be found at this reference: http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-06