CVE-2021-22769

A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly restricted.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:schneider-electric:easergy_t300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:easergy_t300:-:*:*:*:*:*:*:*

History

20 Sep 2021, 13:51

Type Values Removed Values Added
References
  • {'url': 'http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-06', 'name': 'http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-06', 'tags': ['Mitigation', 'Vendor Advisory'], 'refsource': 'MISC'}
  • (MISC) http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-02 - Vendor Advisory
CPE cpe:2.3:a:schneider-electric:enerlin\'x_com\'x_510:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:easergy_t300_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:easergy_t300:-:*:*:*:*:*:*:*
CWE CWE-269 CWE-552

21 Jul 2021, 15:15

Type Values Removed Values Added
Summary A CWE-269: Improper Privilege Management vulnerability exists in EnerlinÕX ComÕX versions prior to V6.8.4 that could cause disclosure of device configuration information to any authenticated user when a specially crafted request is sent to the device. A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly restricted.

22 Jun 2021, 14:40

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.0
v3 : 4.3
References (MISC) http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-06 - (MISC) http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-159-06 - Mitigation, Vendor Advisory
CPE cpe:2.3:a:schneider-electric:enerlin\'x_com\'x_510:*:*:*:*:*:*:*:*
CWE CWE-269

11 Jun 2021, 17:18

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-11 16:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-22769

Mitre link : CVE-2021-22769

CVE.ORG link : CVE-2021-22769


JSON object : View

Products Affected

schneider-electric

  • easergy_t300
  • easergy_t300_firmware
CWE
CWE-552

Files or Directories Accessible to External Parties