CVE-2021-22767 PUBLISHED CVSS 9.800000190734863 CRITICAL

** UNSUPPORTED WHEN ASSIGNED ** A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet.This CVE ID is unique from CVE-2021-22768

EPSS 0.59% · 69.0th percentile

Risk Scores

CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.59%
69.0th percentile

Affected Products

VendorProductVersions
n/aPowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions)PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions)
schneider-electricpowerlogic_egx300_firmware
schneider-electricpowerlogic_egx100_firmware3.0.0

Timeline

References

Open in Interactive Console →