Vulnerabilities > Schneider Electric > Fellerlynk Firmware

DATE CVE VULNERABILITY TITLE RISK
2022-02-11 CVE-2021-22806 Unspecified vulnerability in Schneider-Electric products
A CWE-669: Incorrect Resource Transfer Between Spheres vulnerability exists that could cause data exfiltration and unauthorized access when accessing a malicious website.
network
low complexity
schneider-electric
7.5
2022-02-09 CVE-2022-22809 Unspecified vulnerability in Schneider-Electric products
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could allow modifications of the touch configurations in an unauthorized manner when an attacker attempts to modify the touch configurations.
network
low complexity
schneider-electric
5.3
2022-02-09 CVE-2022-22810 Unspecified vulnerability in Schneider-Electric products
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to manipulate the admin after numerous attempts at guessing credentials.
network
low complexity
schneider-electric
critical
9.8
2022-02-09 CVE-2022-22811 Unspecified vulnerability in Schneider-Electric products
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could induce users to perform unintended actions, leading to the override of the system?s configurations when an attacker persuades a user to visit a rogue website.
network
low complexity
schneider-electric
8.1
2022-02-09 CVE-2022-22812 Unspecified vulnerability in Schneider-Electric products
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause a web session compromise when an attacker injects and then executes arbitrary malicious JavaScript code inside the target browser.
network
low complexity
schneider-electric
6.1