First published: Wed Jul 21 2021(Updated: )
A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a crafted webpage to obtain remote access to the system.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric C-bus Toolkit | <1.15.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22784 is a vulnerability in C-Bus Toolkit v1.15.8 and prior that allows an attacker to obtain remote access to the system.
The severity of CVE-2021-22784 is medium with a CVSS score of 5.7.
CVE-2021-22784 affects Schneider-electric C-bus Toolkit versions up to 1.15.8.
An attacker can exploit CVE-2021-22784 by using a crafted webpage to obtain remote access to the system.
Yes, you can find more information about CVE-2021-22784 at the following references: [Schneider-electric Security Advisory](http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-04) and [Tenable Security Advisory](https://www.tenable.com/security/research/tra-2021-50).