Vulnerability Description
A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to perform unintended actions or access to data when crafted malicious parameters are submitted to the charging station web server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Evlink City Evc1S22P4 Firmware | < r8_v3.4.0.1 |
| Schneider-Electric | Evlink City Evc1S22P4 | - |
| Schneider-Electric | Evlink City Evc1S7P4 Firmware | < r8_v3.4.0.1 |
| Schneider-Electric | Evlink City Evc1S7P4 | - |
| Schneider-Electric | Evlink Parking Evw2 Firmware | < r8_v3.4.0.1 |
| Schneider-Electric | Evlink Parking Evw2 | - |
| Schneider-Electric | Evlink Parking Evf2 Firmware | < r8_v3.4.0.1 |
| Schneider-Electric | Evlink Parking Evf2 | - |
| Schneider-Electric | Evlink Parking Ev.2 Firmware | < r8_v3.4.0.1 |
| Schneider-Electric | Evlink Parking Ev.2 | - |
| Schneider-Electric | Evlink Smart Wallbox Evb1A Firmware | < r8_v3.4.0.1 |
| Schneider-Electric | Evlink Smart Wallbox Evb1A | - |
Related Weaknesses (CWE)
References
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-06Vendor Advisory
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-06Vendor Advisory
FAQ
What is CVE-2021-22726?
CVE-2021-22726 is a vulnerability with a CVSS score of 8.1 (HIGH). A CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 ...
How severe is CVE-2021-22726?
CVE-2021-22726 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22726?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Evlink City Evc1S22P4 Firmware, Schneider-Electric Evlink City Evc1S22P4, Schneider-Electric Evlink City Evc1S7P4 Firmware, Schneider-Electric Evlink City Evc1S7P4, Schneider-Electric Evlink Parking Evw2 Firmware.