CVE-2018-7778

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
03/07/2018
Last modified:
05/09/2018

Description

In Schneider Electric Evlink Charging Station versions prior to v3.2.0-12_v1, the Web Interface has an issue that may allow a remote attacker to gain administrative privileges without properly authenticating remote users.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:schneider-electric:evlink_charging_station_firmware:*:*:*:*:*:*:*:* 3.2.0-12_v1 (excluding)
cpe:2.3:h:schneider-electric:evlink_charging_station:-:*:*:*:*:*:*:*