Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic user information is known by a remote attacker.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Schneider-electric
Subscribe
|
Mcsesm043f23f0
Subscribe
Mcsesm043f23f0 Firmware
Subscribe
Mcsesm053f1cs0
Subscribe
Mcsesm053f1cs0 Firmware
Subscribe
Mcsesm053f1cu0
Subscribe
Mcsesm053f1cu0 Firmware
Subscribe
Mcsesm063f2cs0
Subscribe
Mcsesm063f2cs0 Firmware
Subscribe
Mcsesm063f2cu0
Subscribe
Mcsesm063f2cu0 Firmware
Subscribe
Mcsesm083f23f0
Subscribe
Mcsesm083f23f0 Firmware
Subscribe
Mcsesm083f23f0h
Subscribe
Mcsesm083f23f0h Firmware
Subscribe
Mcsesm093f1cs0
Subscribe
Mcsesm093f1cs0 Firmware
Subscribe
Mcsesm093f1cu0
Subscribe
Mcsesm093f1cu0 Firmware
Subscribe
Mcsesm103f2cs0
Subscribe
Mcsesm103f2cs0 Firmware
Subscribe
Mcsesm103f2cs0h
Subscribe
Mcsesm103f2cs0h Firmware
Subscribe
Mcsesm103f2cu0
Subscribe
Mcsesm103f2cu0 Firmware
Subscribe
Mcsesm103f2cu0h
Subscribe
Mcsesm103f2cu0h Firmware
Subscribe
Mcsesm123f2lg0
Subscribe
Mcsesm123f2lg0 Firmware
Subscribe
Mcsesp083f23g0
Subscribe
Mcsesp083f23g0 Firmware
Subscribe
Mcsesp083f23g0t
Subscribe
Mcsesp083f23g0t Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-9866 | Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic user information is known by a remote attacker. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2024-08-03T18:51:06.977Z
Reserved: 2021-01-06T00:00:00
Link: CVE-2021-22731
No data.
Status : Modified
Published: 2021-05-26T20:15:08.927
Modified: 2024-11-21T05:50:33.060
Link: CVE-2021-22731
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD