CVE-2022-30238: High severity wiser smart eer21000 vulnerability
A CWE-287: Improper Authentication vulnerability exists that could allow an attacker to take over the admin account when an attacker hijacks a session. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-30238?
CVE-2022-30238 has been classified as a serious vulnerability due to its potential to allow attackers to take over admin accounts by hijacking sessions.
How do I fix CVE-2022-30238?
To fix CVE-2022-30238, upgrade to versions later than V4.5 for both Wiser Smart EER21000 and EER21001 firmware.
What products are affected by CVE-2022-30238?
CVE-2022-30238 affects Schneider Electric's Wiser Smart EER21000 and EER21001 firmware versions up to and including V4.5.
What type of vulnerability is CVE-2022-30238?
CVE-2022-30238 is an authentication vulnerability categorized as CWE-287.
Can CVE-2022-30238 be exploited remotely?
Yes, the vulnerability could potentially be exploited remotely, allowing attackers to hijack sessions.