Vulnerability Details CVE-2021-22826
A CWE-20: Improper Input Validation vulnerability exists that could cause arbitrary code execution when the user visits a page containing the injected payload. This CVE is unique from CVE-2021-22827. Affected Product: EcoStruxure� Power Monitoring Expert 9.0 and prior versions
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 70.9%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 6.8
Products affected by CVE-2021-22826
-
cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:7.0
-
cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:8.0
-
cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:8.2
-
cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:9.0