6
CVSSv2

CVE-2021-22825

Published: 28/01/2022 Updated: 03/02/2022
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 8 | Impact Score: 5.9 | Exploitability Score: 2.1
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could allow an malicious user to access the system with elevated privileges when a privileged account clicks on a malicious URL that compromises the security token. Affected Products: AP7xxxx and AP8xxx with NMC2 (V6.9.6 or earlier), AP7xxx and AP8xxx with NMC3 (V1.1.0.3 or earlier), and APDU9xxx with NMC3 (V1.0.0.28 or earlier)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

schneider-electric rack_power_distribution_unit_with_network_management_card_2_firmware

schneider-electric rack_power_distribution_unit_with_network_management_card_3_firmware

ICS Advisories

Schneider Electric Rack PDU (Update A)
Critical Infrastructure Sectors: Energy