CVE-2021-22721: Infoleak
A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to get limited knowledge of javascript code when crafted malicious parameters are submitted to the charging station web server.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-22721.
What is the severity of CVE-2021-22721?
The severity of CVE-2021-22721 is medium with a severity value of 5.3.
Which software versions are affected by CVE-2021-22721?
The affected software versions are EVlink City (EVC1S22P4 / EVC1S7P4) prior to R8 V3.4.0.1, EVlink Parking (EVW2 / EVF2 / EV.2) prior to R8 V3.4.0.1, and EVlink Smart Wallbox (EVB1A) prior to R8 V3.4.0.1.
How can an attacker exploit CVE-2021-22721?
An attacker could exploit CVE-2021-22721 to gain access to sensitive information.
Is there a fix available for CVE-2021-22721?
Yes, the fix for CVE-2021-22721 is to update the affected software versions to R8 V3.4.0.1 or later.