First published: Thu Jun 02 2022(Updated: )
A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to take over the admin account when an attacker hijacks a session. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Wiser Smart Eer21000 Firmware | <=4.5 | |
Schneider-electric Wiser Smart Eer21000 | ||
Schneider-electric Wiser Smart Eer21001 Firmware | <=4.5 | |
Schneider-electric Wiser Smart Eer21001 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30238 has been classified as a serious vulnerability due to its potential to allow attackers to take over admin accounts by hijacking sessions.
To fix CVE-2022-30238, upgrade to versions later than V4.5 for both Wiser Smart EER21000 and EER21001 firmware.
CVE-2022-30238 affects Schneider Electric's Wiser Smart EER21000 and EER21001 firmware versions up to and including V4.5.
CVE-2022-30238 is an authentication vulnerability categorized as CWE-287.
Yes, the vulnerability could potentially be exploited remotely, allowing attackers to hijack sessions.