Schneider Electric Multiple Products Hardcoded Credentials (CVE-2021-22707)

Related Vulnerabilities: CVE-2021-22707  

Check Point Reference: CPAI-2021-2110 Date Published: 29 Feb 2024 Severity: Critical Last Updated: Thursday 29 February, 2024 Source: Industry Reference:CVE-2021-22707
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable? Schneider Electric EVlink City EVC1S22P4 Firmware prior to r8_v3.4.0.1

Schneider Electric EVlink City EVC1S7P4 Firmware prior to r8_v3.4.0.1

Schneider Electric EVlink Parking EVW2 Firmware prior to r8_v3.4.0.1

Schneider Electric EVlink Parking EVF2 Firmware prior to r8_v3.4.0.1

Schneider Electric EVlink Parking EV2 Firmware prior to r8_v3.4.0.1

Schneider Electric EVlink Smart Wallbox EEVB1A Firmware prior to r8_v3.4.0.1 Vulnerability Description A hardcoded credentials vulnerability exists in multiple Schneider Electric products. Successful exploitation of this vulnerability would allow remote attackers to obtain sensitive information and gain unauthorized access into the affected system.