CVE-2021-22784: Medium severity schneider electric spacelogic c-bus toolkit vulnerability
A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a crafted webpage to obtain remote access to the system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-22784?
CVE-2021-22784 is a vulnerability in C-Bus Toolkit v1.15.8 and prior that allows an attacker to obtain remote access to the system.
What is the severity of CVE-2021-22784?
The severity of CVE-2021-22784 is medium with a CVSS score of 5.7.
How does CVE-2021-22784 affect Schneider-electric C-bus Toolkit?
CVE-2021-22784 affects Schneider-electric C-bus Toolkit versions up to 1.15.8.
How can an attacker exploit CVE-2021-22784?
An attacker can exploit CVE-2021-22784 by using a crafted webpage to obtain remote access to the system.
Are there any references for CVE-2021-22784?
Yes, you can find more information about CVE-2021-22784 at the following references: [Schneider-electric Security Advisory](http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-04) and [Tenable Security Advisory](https://www.tenable.com/security/research/tra-2021-50).