CVE-2021-22820: Critical severity schneider-electric evc1s22p4 firmware vulnerability
A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked session to the charger station web server even after the legitimate user account holder has changed his password. Affected Products: EVlink City EVC1S22P4 / EVC1S7P4 (All versions prior to R8 V3.4.0.2 ), EVlink Parking EVW2 / EVF2 / EVP2PE (All versions prior to R8 V3.4.0.2), and EVlink Smart Wallbox EVB1A (All versions prior to R8 V3.4.0.2)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-22820.
What is the severity rating of CVE-2021-22820?
CVE-2021-22820 has a severity rating of 9.8 (critical).
What is the affected software?
The affected software includes Schneider-electric Evlink City EVC1S22P4 Firmware up to version 3.4.0.2.
What is the impact of this vulnerability?
This vulnerability allows an attacker to maintain an unauthorized access over a hijacked session to the charger station web server even after the legitimate user account holder has changed their password.
How can I fix CVE-2021-22820?
To fix CVE-2021-22820, it is recommended to update the Schneider-electric Evlink City EVC1S22P4 Firmware to a version beyond 3.4.0.2.