CVE-2021-22774: High severity schneider-electric evc1s22p4 firmware vulnerability
A CWE-759: Use of a One-Way Hash without a Salt vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could lead an attacker to get knowledge of charging station user account credentials using dictionary attacks techniques.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-22774.
What is the severity of CVE-2021-22774?
The severity of CVE-2021-22774 is high with a CVSS score of 7.5.
Which products are affected by CVE-2021-22774?
CVE-2021-22774 affects EVlink City (EVC1S22P4), EVlink Parking (EVW2 / EVF2 / EV.2), and EVlink Smart Wallbox (EVB1A) prior to firmware version R8 V3.4.0.1.
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-759.
How can I fix CVE-2021-22774?
To fix CVE-2021-22774, update the firmware of EVlink City (EVC1S22P4), EVlink Parking (EVW2 / EVF2 / EV.2), and EVlink Smart Wallbox (EVB1A) to version R8 V3.4.0.1 or later.