CVE-2021-22716: High severity schneider electric spacelogic c-bus toolkit vulnerability
A CWE-732: Incorrect Permission Assignment for Critical Resource vulnerability exists that could allow remote code execution when an unprivileged user modifies a file. Affected Product: C-Bus Toolkit (V1.15.9 and prior)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-22716.
What is the title of the vulnerability?
The title of the vulnerability is "Incorrect Permission Assignment for Critical Resource vulnerability".
How does the vulnerability occur?
The vulnerability occurs when an unprivileged user modifies a file.
What product is affected by the vulnerability?
The affected product is C-Bus Toolkit (V1.15.9 and prior).
What is the severity of the vulnerability?
The severity of the vulnerability is high with a CVSS score of 7.8.
Are there any references available for this vulnerability?
Yes, there are references available. You can find them at the following links: [Schneider-electric Security and Safety Notice](https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-103-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2021-103-01_C-Bus_Toolkit_C-Gate_Server_Security_Notification.pdf) and [US-CERT ICS Advisory](https://us-cert.cisa.gov/ics/advisories/icsa-21-105-01).
What is CWE-732?
CWE-732 refers to the Incorrect Permission Assignment for Critical Resource vulnerability.