First published: Fri Jan 28 2022(Updated: )
A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22826. Affected Product: EcoStruxure? Power Monitoring Expert 9.0 and prior versions
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric EcoStruxure Power Monitoring Expert | <=9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-22827 is a CVE identifier for a CWE-20: Improper Input Validation vulnerability in EcoStruxure Power Monitoring Expert version 9.0 and prior.
CVE-2021-22827 could allow an attacker to execute arbitrary code by visiting a page containing a specially crafted payload.
CVE-2021-22827 is separate and unique from CVE-2021-22826.
EcoStruxure Power Monitoring Expert versions 9.0 and prior are affected by CVE-2021-22827.
CVE-2021-22827 has a severity score of 8.8, which is classified as high.