First published: Fri Jan 28 2022(Updated: )
A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22827. Affected Product: EcoStruxure? Power Monitoring Expert 9.0 and prior versions
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric EcoStruxure Power Monitoring Expert | <=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22826 is a vulnerability classified as CWE-20: Improper Input Validation that could lead to arbitrary code execution when a user visits a page with an injected payload.
The severity of CVE-2021-22826 is high, with a severity value of 8.8.
CVE-2021-22826 affects EcoStruxure Power Monitoring Expert 9.0 and prior versions.
CVE-2021-22826 can be exploited by visiting a page that contains the injected payload.
Please refer to the documentation provided by Schneider-electric for information on how to fix CVE-2021-22826.