← Back

CVE-2021-22725

nvd nist
Published: Jan 28, 2022Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A CVE-352 Cross-Site Request Forgery (CSRF) vulnerability exists that could allow an attacker to impersonate the user or carry out actions on their behalf when crafted malicious parameters are submitted in POST requests sent to the charging station web server. Affected Products: EVlink City EVC1S22P4 / EVC1S7P4 (All versions prior to R8 V3.4.0.2 ), EVlink Parking EVW2 / EVF2 / EVP2PE (All versions prior to R8 V3.4.0.2), and EVlink Smart Wallbox EVB1A (All versions prior to R8 V3.4.0.2)

Affected (6)

Evc1s22p4 Firmware
Evc1s7p4 Firmware
Evw2 Firmware
Evf2 Firmware
Evp2pe Firmware
Evb1a Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.4.0.2
Running on/withPlatform Versions
Schneider Electric
Evc1s22p4
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.4.0.2
Running on/withPlatform Versions
Schneider Electric
Evc1s7p4
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.4.0.2
Running on/withPlatform Versions
Schneider Electric
Evw2
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.4.0.2
Running on/withPlatform Versions
Schneider Electric
Evf2
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.4.0.2
Running on/withPlatform Versions
Schneider Electric
Evp2pe
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 3.4.0.2
Running on/withPlatform Versions
Schneider Electric
Evb1a
All versions

References (2)

Source: cybersecurity@se.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.