Weak Password Recovery Mechanism for Forgotten Password vulnerability exists on Modicon Managed Switch MCSESM* and MCSESP* V8.21 and prior which could cause an unauthorized password change through HTTP / HTTPS when basic user information is known by a remote attacker.
References
Link | Resource |
---|---|
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-01 | Patch Vendor Advisory |
https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-01 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
Configuration 11 (hide)
AND |
|
Configuration 12 (hide)
AND |
|
Configuration 13 (hide)
AND |
|
Configuration 14 (hide)
AND |
|
Configuration 15 (hide)
AND |
|
Configuration 16 (hide)
AND |
|
History
21 Nov 2024, 05:50
Type | Values Removed | Values Added |
---|---|---|
References | () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-01 - Patch, Vendor Advisory |
01 Feb 2022, 18:12
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:schenider-electric:mcsesm053f1cs0_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm043f23f0:-:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm103f2cu0_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm103f2cu0h:-:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesp083f23g0t_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm063f2cu0:-:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm083f23f0:-:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm043f23f0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm093f1cs0_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm103f2cu0:-:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm103f2cs0h_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm053f1cu0_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm103f2cs0:-:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm093f1cu0:-:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm083f23f0_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm053f1cs0:-:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesp083f23g0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm063f2cs0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm103f2cu0h_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm103f2cs0h:-:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesp083f23g0:-:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm053f1cu0:-:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm093f1cu0_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesp083f23g0t:-:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm123f2lg0:-:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm083f23f0h_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm063f2cs0:-:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm093f1cs0:-:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm103f2cs0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm063f2cu0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm123f2lg0_firmware:*:*:*:*:*:*:*:* |
cpe:2.3:h:schneider-electric:mcsesm093f1cs0:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:mcsesm103f2cs0:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:mcsesm093f1cs0_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:mcsesm043f23f0:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:mcsesm083f23f0h_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:mcsesp083f23g0t:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:mcsesm053f1cs0:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:mcsesm103f2cu0_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:mcsesm063f2cs0:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:mcsesm053f1cu0:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:mcsesm053f1cu0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:mcsesp083f23g0_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:mcsesm103f2cu0h:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:mcsesm103f2cs0_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:mcsesm123f2lg0:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:mcsesm093f1cu0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:mcsesp083f23g0t_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:mcsesm083f23f0h:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:mcsesm063f2cu0:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:mcsesm103f2cu0:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:mcsesm043f23f0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:mcsesm053f1cs0_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:mcsesm103f2cs0h:-:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:mcsesm083f23f0:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:mcsesm083f23f0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:mcsesm123f2lg0_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:mcsesp083f23g0:-:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:mcsesm103f2cu0h_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:mcsesm063f2cu0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:mcsesm063f2cs0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schneider-electric:mcsesm103f2cs0h_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schneider-electric:mcsesm093f1cu0:-:*:*:*:*:*:*:* |
04 Jun 2021, 16:14
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-130-01 - Patch, Vendor Advisory | |
CPE | cpe:2.3:h:schenider-electric:mcsesm103f2cu0:-:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesp083f23g0t_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm103f2cs0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm083f23f0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm123f2lg0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm103f2cu0h_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm093f1cs0_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm063f2cs0:-:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm083f23f0:-:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm043f23f0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesp083f23g0_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm123f2lg0:-:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm103f2cs0:-:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm053f1cu0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm063f2cu0_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm043f23f0:-:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm063f2cu0:-:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesp083f23g0:-:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm053f1cs0:-:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm063f2cs0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm103f2cu0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm093f1cu0_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm103f2cs0h:-:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm083f23f0h:-:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm103f2cs0h_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm053f1cs0_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm093f1cs0:-:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesp083f23g0t:-:*:*:*:*:*:*:* cpe:2.3:o:schenider-electric:mcsesm083f23f0h_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm093f1cu0:-:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm103f2cu0h:-:*:*:*:*:*:*:* cpe:2.3:h:schenider-electric:mcsesm053f1cu0:-:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : 7.5
v3 : 9.8 |
26 May 2021, 20:49
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-640 |
26 May 2021, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-05-26 20:15
Updated : 2024-11-21 05:50
NVD link : CVE-2021-22731
Mitre link : CVE-2021-22731
CVE.ORG link : CVE-2021-22731
JSON object : View
Products Affected
schneider-electric
- mcsesm123f2lg0
- mcsesm103f2cs0h_firmware
- mcsesm103f2cs0_firmware
- mcsesm103f2cs0
- mcsesm063f2cs0
- mcsesp083f23g0t
- mcsesm103f2cu0_firmware
- mcsesm103f2cu0
- mcsesm053f1cu0_firmware
- mcsesm083f23f0h
- mcsesp083f23g0
- mcsesm083f23f0
- mcsesp083f23g0t_firmware
- mcsesm063f2cu0
- mcsesm103f2cu0h
- mcsesm043f23f0
- mcsesm103f2cs0h
- mcsesm053f1cs0_firmware
- mcsesm093f1cu0
- mcsesm093f1cs0_firmware
- mcsesm043f23f0_firmware
- mcsesm083f23f0h_firmware
- mcsesm053f1cs0
- mcsesm083f23f0_firmware
- mcsesm103f2cu0h_firmware
- mcsesm063f2cs0_firmware
- mcsesm053f1cu0
- mcsesm093f1cu0_firmware
- mcsesm093f1cs0
- mcsesp083f23g0_firmware
- mcsesm123f2lg0_firmware
- mcsesm063f2cu0_firmware
CWE
CWE-640
Weak Password Recovery Mechanism for Forgotten Password