PT-2022-15690 · Schneider Electric · Ecostruxure Ev Charging Expert

Published

2022-02-09

·

Updated

2023-02-02

·

CVE-2022-22808

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EcoStruxure EV Charging Expert (formerly known as EVlink Load Management System) versions prior to V4.0.0.13
Description A Cross-Site Request Forgery (CSRF) issue exists, allowing a remote attacker to gain unauthorized access to the product by conducting cross-domain attacks based on same-origin policy or cross-site request forgery protections bypass.
Recommendations For versions prior to V4.0.0.13, update to version V4.0.0.13 or later to resolve the issue.

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2022-22808

Affected Products

Ecostruxure Ev Charging Expert