Vulnerability Description
A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T200 ((Modbus) SC2-04MOD-07000100 and earlier), Easergy T200 ((IEC104) SC2-04IEC-07000100 and earlier), and Easergy T200 ((DNP3) SC2-04DNP-07000102 and earlier) that could cause unauthorized operation when authentication is bypassed.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | T200I Firmware | <= sc2-04mod-07000100 |
| Schneider-Electric | T200I | - |
| Schneider-Electric | T200E Firmware | <= sc2-04mod-07000100 |
| Schneider-Electric | T200E | - |
| Schneider-Electric | T200P Firmware | <= sc2-04mod-07000100 |
| Schneider-Electric | T200P | - |
Related Weaknesses (CWE)
References
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-05Vendor Advisory
- http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-05Vendor Advisory
FAQ
What is CVE-2021-22772?
CVE-2021-22772 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A CWE-306: Missing Authentication for Critical Function vulnerability exists in Easergy T200 ((Modbus) SC2-04MOD-07000100 and earlier), Easergy T200 ((IEC104) SC2-04IEC-07000100 and earlier), and Ease...
How severe is CVE-2021-22772?
CVE-2021-22772 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-22772?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric T200I Firmware, Schneider-Electric T200I, Schneider-Electric T200E Firmware, Schneider-Electric T200E, Schneider-Electric T200P Firmware.