Description
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could allow an attacker to access the system with elevated privileges when a privileged account clicks on a malicious URL that compromises the security token. Affected Products: AP7xxxx and AP8xxx with NMC2 (V6.9.6 or earlier), AP7xxx and AP8xxx with NMC3 (V1.1.0.3 or earlier), and APDU9xxx with NMC3 (V1.0.0.28 or earlier)
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-9960 | A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could allow an attacker to access the system with elevated privileges when a privileged account clicks on a malicious URL that compromises the security token. Affected Products: AP7xxxx and AP8xxx with NMC2 (V6.9.6 or earlier), AP7xxx and AP8xxx with NMC3 (V1.1.0.3 or earlier), and APDU9xxx with NMC3 (V1.0.0.28 or earlier) |
References
History
Mon, 08 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Subscriptions
Schneider-electric
Subscribe
Rack Power Distribution Unit With Network Management Card 2
Subscribe
Rack Power Distribution Unit With Network Management Card 2 Firmware
Subscribe
Rack Power Distribution Unit With Network Management Card 3
Subscribe
Rack Power Distribution Unit With Network Management Card 3 Firmware
Subscribe
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2025-09-08T16:09:21.462Z
Reserved: 2021-01-06T00:00:00.000Z
Link: CVE-2021-22825
Updated: 2024-08-03T18:51:07.440Z
Status : Modified
Published: 2022-01-28T20:15:10.627
Modified: 2025-09-08T16:15:33.657
Link: CVE-2021-22825
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD