Vulnerability Description
A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked session to the charger station web server even after the legitimate user account holder has changed his password. Affected Products: EVlink City EVC1S22P4 / EVC1S7P4 (All versions prior to R8 V3.4.0.2 ), EVlink Parking EVW2 / EVF2 / EVP2PE (All versions prior to R8 V3.4.0.2), and EVlink Smart Wallbox EVB1A (All versions prior to R8 V3.4.0.2)
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Evlink City Evc1S22P4 Firmware | < 3.4.0.2 |
| Schneider-Electric | Evlink City Evc1S22P4 | - |
| Schneider-Electric | Evlink City Evc1S7P4 Firmware | < 3.4.0.2 |
| Schneider-Electric | Evlink City Evc1S7P4 | - |
| Schneider-Electric | Evlink Parking Evw2 Firmware | < 3.4.0.2 |
| Schneider-Electric | Evlink Parking Evw2 | - |
| Schneider-Electric | Evlink Parking Evf2 Firmware | < 3.4.0.2 |
| Schneider-Electric | Evlink Parking Evf2 | - |
| Schneider-Electric | Evlink Parking Evp2Pe Firmware | < 3.4.0.2 |
| Schneider-Electric | Evlink Parking Evp2Pe | - |
| Schneider-Electric | Evlink Smart Wallbox Evb1A Firmware | < 3.4.0.2 |
| Schneider-Electric | Evlink Smart Wallbox Evb1A | - |
Related Weaknesses (CWE)
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-348-02PatchVendor Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-348-02PatchVendor Advisory
FAQ
What is CVE-2021-22820?
CVE-2021-22820 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A CWE-614 Insufficient Session Expiration vulnerability exists that could allow an attacker to maintain an unauthorized access over a hijacked session to the charger station web server even after the ...
How severe is CVE-2021-22820?
CVE-2021-22820 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-22820?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Evlink City Evc1S22P4 Firmware, Schneider-Electric Evlink City Evc1S22P4, Schneider-Electric Evlink City Evc1S7P4 Firmware, Schneider-Electric Evlink City Evc1S7P4, Schneider-Electric Evlink Parking Evw2 Firmware.