Vulnerabilities > CVE-2021-22771 - Unspecified vulnerability in Schneider-Electric Easergy T300 Firmware 1.5.2/2.7/2.7.1

047910
CVSS 7.3 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
schneider-electric

Summary

A CWE-1236: Improper Neutralization of Formula Elements in a CSV File vulnerability exists in Easergy T300 with firmware V2.7.1 and older that would allow arbitrary command execution.