#VU57376 Improper Privilege Management in ConneXium Network Manager - CVE-2021-22801 

 

#VU57376 Improper Privilege Management in ConneXium Network Manager - CVE-2021-22801

Published: October 15, 2021


Vulnerability identifier: #VU57376
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2021-22801
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
ConneXium Network Manager
Software vendor:
Schneider Electric

Description

The vulnerability allows a remote attacker to escalate privileges.

The vulnerability exists due to improper privilege management. A remote attacker can execute arbitrary commands when the software is configured with specially crafted event actions.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links