CVE-2021-22827: Input Validation
A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22826. Affected Product: EcoStruxure? Power Monitoring Expert 9.0 and prior versions
Other sources
A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22826. Affected Product: EcoStruxure� Power Monitoring Expert 9.0 and prior versions
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-22827?
CVE-2021-22827 is a CVE identifier for a CWE-20: Improper Input Validation vulnerability in EcoStruxure Power Monitoring Expert version 9.0 and prior.
How does CVE-2021-22827 impact users?
CVE-2021-22827 could allow an attacker to execute arbitrary code by visiting a page containing a specially crafted payload.
Is CVE-2021-22827 related to CVE-2021-22826?
CVE-2021-22827 is separate and unique from CVE-2021-22826.
What software versions are affected by CVE-2021-22827?
EcoStruxure Power Monitoring Expert versions 9.0 and prior are affected by CVE-2021-22827.
How severe is CVE-2021-22827?
CVE-2021-22827 has a severity score of 8.8, which is classified as high.