CVE-2021-22767
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
11/06/2021
Last modified:
03/08/2024
Description
A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet.This CVE ID is unique from CVE-2021-2276
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:schneider-electric:powerlogic_egx100_firmware:*:*:*:*:*:*:*:* | 3.0.0 (including) | |
cpe:2.3:h:schneider-electric:powerlogic_egx100:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:schneider-electric:powerlogic_egx300_firmware:*:*:*:*:*:*:*:* | ||
cpe:2.3:h:schneider-electric:powerlogic_egx300:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page