Vulnerability Description
A CWE-798: Use of Hard-coded Credentials vulnerability exists that could allow arbitrary code to be executed when root level access is obtained. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Wiser Smart Eer21000 Firmware | <= 4.5 |
| Schneider-Electric | Wiser Smart Eer21000 | - |
| Schneider-Electric | Wiser Smart Eer21001 Firmware | <= 4.5 |
| Schneider-Electric | Wiser Smart Eer21001 | - |
Related Weaknesses (CWE)
References
- https://www.se.com/ww/en/download/document/SEVD-2022-130-03/MitigationVendor Advisory
- https://www.se.com/ww/en/download/document/SEVD-2022-130-03/MitigationVendor Advisory
FAQ
What is CVE-2022-30234?
CVE-2022-30234 is a vulnerability with a CVSS score of 9.4 (CRITICAL). A CWE-798: Use of Hard-coded Credentials vulnerability exists that could allow arbitrary code to be executed when root level access is obtained. Affected Products: Wiser Smart, EER21000 & EER21001 (V4...
How severe is CVE-2022-30234?
CVE-2022-30234 has been rated CRITICAL with a CVSS base score of 9.4/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-30234?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Wiser Smart Eer21000 Firmware, Schneider-Electric Wiser Smart Eer21000, Schneider-Electric Wiser Smart Eer21001 Firmware, Schneider-Electric Wiser Smart Eer21001.