5.5
CVE-2021-22781
- EPSS 0.05%
- Published 14.07.2021 15:15:08
- Last modified 21.11.2024 05:50:39
- Source cybersecurity@se.com
- Teams watchlist Login
- Open Login
Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versions of Unity Pro), EcoStruxure Process Expert (all versions, including all versions of EcoStruxure Hybrid DCS), and SCADAPack RemoteConnect for x70, all versions, that could cause a leak of SMTP credential used for mailbox authentication when an attacker can access a project file.
Data is provided by the National Vulnerability Database (NVD)
Schneider-electric ≫ Ecostruxure Control Expert Version < 15.0
Schneider-electric ≫ Ecostruxure Control Expert Version15.0 Update-
Schneider-electric ≫ Remoteconnect HwPlatformscadapack_x70
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.05% | 0.13 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.