VDB

SEVD-2022-039-02

SEVD-2022-039-02 PUBLISHED CVSS 8.199999809265137 HIGH

Schneider Electric is aware of multiple vulnerabilities in its EcoStruxure EV Charging Expert (formerly known as EVlink Load Management System) products. The EcoStruxure EV Charging Expert products are load management, access management and supervision solutions for EV charging infrastructure. Failure to apply the available remediations may risk potential unauthorized access to the product’s web server, which could lead to tampering and compromise of the product’s settings and accounts. Such tampering could lead to things like denial of service attacks, which could result in unauthorized use of the managed EV charging stations, service interruptions, failure to communicate with the supervision system and the modification and disclosure of the product’s configuration. In addition to applying the available remediations, to limit the risk of a product being compromised, Schneider Electric recommends that customers follow and apply network security best practices and ensure that the products are not accessible from the internet, as outlined in the General Security Recommendations section

Risk Scores

CVSS v3.1
8.199999809265137
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Affected Products

VendorProductVersions
Schneider Electric EcoStruxure EV Charging versions prior to SP8 (Version 01) V4.0.0.13
Schneider Electric EcoStruxure EV Charging SP8 (Version 01) V4.0.0.13

Timeline

  • Feb 8, 2022 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›