CVE-2021-22784
medium · 5.7A CWE-306: Missing Authentication for Critical Function vulnerability exists in C-Bus Toolkit v1.15.8 and prior that could allow an attacker to use a crafted webpage to obtain remote access to the system.
5.7
CVSS
12.1%
EPSS (exploit prob.)
96th
EPSS percentile
2021-07-21
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Weaknesses
CWE-306
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| schneider-electric | c-bus_toolkit | < 1.15.9 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-22784