VDB
CVE-2021-22765
CVE-2021-22765
PUBLISHED
CVSS 7.5 HIGH
A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet
EPSS 0.61% · 70.1th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
0.61%
70.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) | PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) |
| schneider-electric | powerlogic_egx300_firmware | |
| schneider-electric | powerlogic_egx100_firmware | 3.0.0 |
Exploit Intelligence
Timeline
- Jun 9, 2021 CVE Published
- Jun 12, 2021 EPSS Score
- Aug 13, 2021 EPSS Score
- Oct 12, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Feb 11, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 13, 2022 EPSS Score
- Aug 13, 2022 EPSS Score
- Oct 13, 2022 EPSS Score
- Dec 13, 2022 EPSS Score
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-03 advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-04 advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-05 advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-01 advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-02 advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-06 advisory
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-03 url
- https://nvd.nist.gov/vuln/detail/CVE-2021-22765 advisory