Lucene search

K
cvelistSchneiderCVELIST:CVE-2021-22795
HistoryMar 28, 2022 - 4:25 p.m.

CVE-2021-22795

2022-03-2816:25:23
CWE-78
schneider
www.cve.org
4
cwe-78
os command injection
struxureware data center expert
remote code execution
network vulnerability
affected product

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

10

Confidence

High

EPSS

0.004

Percentile

73.1%

A CWE-78 Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability exists that could cause remote code execution when performed over the network. Affected Product: StruxureWare Data Center Expert (V7.8.1 and prior)

CNA Affected

[
  {
    "product": "StruxureWare Data Center Expert",
    "vendor": "Schneider Electric",
    "versions": [
      {
        "lessThan": "V7.8.1",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

10

Confidence

High

EPSS

0.004

Percentile

73.1%

Related for CVELIST:CVE-2021-22795