Vulnerabilities > Rittal > CMC PU III 7030 000 Firmware

DATE CVE VULNERABILITY TITLE RISK
2021-09-09 CVE-2021-40222 OS Command Injection vulnerability in Rittal CMC PU III 7030.000 Firmware 3.11.002/3.15.704
Rittal CMC PU III Web management Version affected: V3.11.00_2.
network
low complexity
rittal CWE-78
critical
9.0
2021-09-09 CVE-2021-40223 Cross-site Scripting vulnerability in Rittal CMC PU III 7030.000 Firmware 3.11.002/3.15.704
Rittal CMC PU III Web management (version V3.11.00_2) fails to sanitize user input on several parameters of the configuration (User Configuration dialog, Task Configuration dialog and set logging filter dialog).
network
rittal CWE-79
3.5