CVE-2021-22769: Medium severity Schneider-electric Easergy T300 Firmware vulnerability
Published Jun 11, 2021
·Updated
A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly restricted.
Affected Software
4 affected components
Schneider-electric Easergy T300 Firmware<=2.7.1
Schneider-electric Easergy T300
All of the following
Schneider-electric Easergy T300 Firmware<=2.7.1
Schneider-electric Easergy T300
Event History
Jun 11, 2021
CVE Published
via MITRE·03:40 PM
Data Sourced
via MITRE·03:40 PM
DescriptionWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-22769.
2
What is the severity of CVE-2021-22769?
The severity of CVE-2021-22769 is medium with a severity value of 4.3.
3
Which software versions are affected by CVE-2021-22769?
Easergy T300 firmware versions up to and including 2.7.1 are affected by CVE-2021-22769.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by external parties who can access files or directories when access is not properly restricted.
5
Is there a fix available for CVE-2021-22769?
It is recommended to update to a version of Easergy T300 firmware that is not affected by CVE-2021-22769.