PT-2022-3205 · Schneider Electric · Wiser Controller Eer21000+2

Published

2022-05-10

·

Updated

2022-06-13

·

CVE-2022-30238

CVSS v2.0

9.7

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:P
Name of the Vulnerable Software and Affected Versions Wiser Smart versions prior to 4.5 Wiser Controller EER21000 versions prior to 4.5 Wiser Controller EER21001 versions prior to 4.5
Description The issue is related to errors in the authentication procedure of the Wiser Smart programmable logic controllers, specifically the Schneider Electric Wiser Controller EER21000 and Wiser Controller EER21001. This could allow a remote attacker to gain unauthorized access to protected information by hijacking a session and taking over the admin account.
Recommendations For Wiser Smart versions prior to 4.5, update to a version later than 4.5 to resolve the issue. For Wiser Controller EER21000 versions prior to 4.5, update to a version later than 4.5 to resolve the issue. For Wiser Controller EER21001 versions prior to 4.5, update to a version later than 4.5 to resolve the issue. As a temporary workaround, consider restricting access to the admin account until a patch is available.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03896
CVE-2022-30238

Affected Products

Wiser Controller Eer21000
Wiser Controller Eer21001
Wiser Smart