CVE-2021-22826: Input Validation
A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22827. Affected Product: EcoStruxure? Power Monitoring Expert 9.0 and prior versions
Other sources
A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22827. Affected Product: EcoStruxure� Power Monitoring Expert 9.0 and prior versions
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-22826?
CVE-2021-22826 is a vulnerability classified as CWE-20: Improper Input Validation that could lead to arbitrary code execution when a user visits a page with an injected payload.
What is the severity of CVE-2021-22826?
The severity of CVE-2021-22826 is high, with a severity value of 8.8.
Which product is affected by CVE-2021-22826?
CVE-2021-22826 affects EcoStruxure Power Monitoring Expert 9.0 and prior versions.
How can CVE-2021-22826 be exploited?
CVE-2021-22826 can be exploited by visiting a page that contains the injected payload.
Is there a fix available for CVE-2021-22826?
Please refer to the documentation provided by Schneider-electric for information on how to fix CVE-2021-22826.