CVE-2021-22771: High severity schneider electric easergy t300 firmware vulnerability
Published Jul 21, 2021
·Updated
A CWE-1236: Improper Neutralization of Formula Elements in a CSV File vulnerability exists in Easergy T300 with firmware V2.7.1 and older that would allow arbitrary command execution.
Affected Software
2 affected components
Schneider-electric Easergy T300 Firmware<=2.7.1
Schneider-electric Easergy T300
Event History
Jul 21, 2021
CVE Published
via MITRE·10:40 AM
Data Sourced
via MITRE·10:40 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22771?
CVE-2021-22771 is considered a high severity vulnerability due to its potential for arbitrary command execution.
2
How do I fix CVE-2021-22771?
To fix CVE-2021-22771, upgrade to Easergy T300 firmware version 2.7.2 or later.
3
What type of vulnerability is CVE-2021-22771?
CVE-2021-22771 is classified as CWE-1236, which involves improper neutralization of formula elements in a CSV file.
4
Which firmware versions are affected by CVE-2021-22771?
CVE-2021-22771 affects Easergy T300 firmware versions 2.7.1 and older.
5
Can CVE-2021-22771 be exploited remotely?
Yes, CVE-2021-22771 can be exploited remotely, allowing attackers to execute arbitrary commands.