Description
A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause a user to perform an unintended action on the target device when using the HTTP web interface.
Published: 2021-02-19
Score: 4.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-9836 A CWE-352: Cross-Site Request Forgery vulnerability exists in PowerLogic ION7400, ION7650, ION83xx/84xx/85xx/8600, ION8650, ION8800, ION9000 and PM800 (see notification for affected versions), that could cause a user to perform an unintended action on the target device when using the HTTP web interface.
History

No history.

Subscriptions

Schneider-electric Powerlogic Ion7400 Powerlogic Ion7400 Firmware Powerlogic Ion7410 Powerlogic Ion7650 Powerlogic Ion7650 Firmware Powerlogic Ion8300 Powerlogic Ion8300 Firmware Powerlogic Ion8400 Powerlogic Ion8400 Firmware Powerlogic Ion8500 Powerlogic Ion8500 Firmware Powerlogic Ion8600 Powerlogic Ion8600 Firmware Powerlogic Ion8650 Powerlogic Ion8650 Firmware Powerlogic Ion8800 Powerlogic Ion8800 Firmware Powerlogic Ion9000 Powerlogic Ion9000 Firmware Powerlogic Pm8000 Powerlogic Pm8000 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: schneider

Published:

Updated: 2024-08-03T18:51:07.099Z

Reserved: 2021-01-06T00:00:00.000Z

Link: CVE-2021-22701

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-02-19T16:15:12.937

Modified: 2024-11-21T05:50:29.377

Link: CVE-2021-22701

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses