Vulnerability Description
A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could cause disclosure of encrypted credentials when consulting the maintenance report.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Evlink City Evc1S22P4 Firmware | < r8_v3.4.0.1 |
| Schneider-Electric | Evlink City Evc1S22P4 | - |
| Schneider-Electric | Evlink City Evc1S7P4 Firmware | < r8_v3.4.0.1 |
| Schneider-Electric | Evlink City Evc1S7P4 | - |
| Schneider-Electric | Evlink Parking Evw2 Firmware | < r8_v3.4.0.1 |
| Schneider-Electric | Evlink Parking Evw2 | - |
| Schneider-Electric | Evlink Parking Evf2 Firmware | < r8_v3.4.0.1 |
| Schneider-Electric | Evlink Parking Evf2 | - |
| Schneider-Electric | Evlink Parking Ev.2 Firmware | < r8_v3.4.0.1 |
| Schneider-Electric | Evlink Parking Ev.2 | - |
| Schneider-Electric | Evlink Smart Wallbox Evb1A Firmware | < r8_v3.4.0.1 |
| Schneider-Electric | Evlink Smart Wallbox Evb1A | - |
Related Weaknesses (CWE)
References
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-06Vendor Advisory
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-06Vendor Advisory
FAQ
What is CVE-2021-22728?
CVE-2021-22728 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A CWE-200: Information Exposure vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and...
How severe is CVE-2021-22728?
CVE-2021-22728 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22728?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Evlink City Evc1S22P4 Firmware, Schneider-Electric Evlink City Evc1S22P4, Schneider-Electric Evlink City Evc1S7P4 Firmware, Schneider-Electric Evlink City Evc1S7P4, Schneider-Electric Evlink Parking Evw2 Firmware.