Vulnerability Description
A CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to gain unauthorized access to the charging station web server
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Evlink City Evc1S22P4 Firmware | < r8_v3.4.0.1 |
| Schneider-Electric | Evlink City Evc1S22P4 | - |
| Schneider-Electric | Evlink City Evc1S7P4 Firmware | < r8_v3.4.0.1 |
| Schneider-Electric | Evlink City Evc1S7P4 | - |
| Schneider-Electric | Evlink Parking Evw2 Firmware | < r8_v3.4.0.1 |
| Schneider-Electric | Evlink Parking Evw2 | - |
| Schneider-Electric | Evlink Parking Evf2 Firmware | < r8_v3.4.0.1 |
| Schneider-Electric | Evlink Parking Evf2 | - |
| Schneider-Electric | Evlink Parking Ev.2 Firmware | < r8_v3.4.0.1 |
| Schneider-Electric | Evlink Parking Ev.2 | - |
| Schneider-Electric | Evlink Smart Wallbox Evb1A Firmware | < r8_v3.4.0.1 |
| Schneider-Electric | Evlink Smart Wallbox Evb1A | - |
Related Weaknesses (CWE)
References
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-06Vendor Advisory
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-06Vendor Advisory
FAQ
What is CVE-2021-22727?
CVE-2021-22727 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A CWE-331: Insufficient Entropy vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and...
How severe is CVE-2021-22727?
CVE-2021-22727 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-22727?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Evlink City Evc1S22P4 Firmware, Schneider-Electric Evlink City Evc1S22P4, Schneider-Electric Evlink City Evc1S7P4 Firmware, Schneider-Electric Evlink City Evc1S7P4, Schneider-Electric Evlink Parking Evw2 Firmware.