First published: Fri Jun 11 2021(Updated: )
A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly restricted.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Easergy T300 Firmware | <=2.7.1 | |
Schneider-electric Easergy T300 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-22769.
The severity of CVE-2021-22769 is medium with a severity value of 4.3.
Easergy T300 firmware versions up to and including 2.7.1 are affected by CVE-2021-22769.
This vulnerability can be exploited by external parties who can access files or directories when access is not properly restricted.
It is recommended to update to a version of Easergy T300 firmware that is not affected by CVE-2021-22769.