PT-2022-9294 · Schneider Electric · Ecostruxure Power Monitoring Expert

Published

2022-01-28

·

Updated

2023-01-30

·

CVE-2021-22826

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EcoStruxure Power Monitoring Expert versions 9.0 and prior
Description A vulnerability exists due to improper input validation, which could lead to arbitrary code execution when a user visits a page containing a malicious payload.
Recommendations For versions 9.0 and prior, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

CVE-2021-22826

Affected Products

Ecostruxure Power Monitoring Expert