IM
IronMonkey Threat Research

CVE-2021-22784 MEDIUM

Published: 2021-07-21 | Last Modified: 2024-11-21 | Status: Modified

Description

A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a crafted webpage to obtain remote access to the system.

Additional Descriptions (1)

A CWE-306: Se presenta una vulnerabilidad de Falta de Autentificación para una Función Crítica en C-Bus Toolkit versiones v1.15.8 y anteriores, que podría permitir a un atacante usar una página web diseñada para obtener acceso remoto al sistema

CVSS Metrics

Base Score: 5.7 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionREQUIRED
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactHIGH
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 2.1

Impact Score: 3.6

Base Score: 3.5 (LOW)

AV:N/AC:M/Au:S/C:N/I:P/A:N

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationSINGLE
Confidentiality ImpactNONE
Integrity ImpactPARTIAL
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 6.8

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-306

Affected Products

Vendor Product Version Update Type
schneider-electric c-bus_toolkit * <built-in method update of dict object at 0x7e60ba04c780> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:c-bus_toolkit:*:*:*:*:*:*:*:*

References

Notification
Message here