CVE-2021-22821

A CWE-918 Server-Side Request Forgery (SSRF) vulnerability exists that could cause the station web server to forward requests to unintended network targets when crafted malicious parameters are submitted to the charging station web server. Affected Products: EVlink City EVC1S22P4 / EVC1S7P4 (All versions prior to R8 V3.4.0.2 ), EVlink Parking EVW2 / EVF2 / EVP2PE (All versions prior to R8 V3.4.0.2), and EVlink Smart Wallbox EVB1A (All versions prior to R8 V3.4.0.2)
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:schneider-electric:evlink_city_evc1s22p4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:evlink_city_evc1s22p4:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:schneider-electric:evlink_city_evc1s7p4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:evlink_city_evc1s7p4:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:schneider-electric:evlink_parking_evw2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:evlink_parking_evw2:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:schneider-electric:evlink_parking_evf2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:evlink_parking_evf2:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:schneider-electric:evlink_parking_evp2pe_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:evlink_parking_evp2pe:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:schneider-electric:evlink_smart_wallbox_evb1a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:schneider-electric:evlink_smart_wallbox_evb1a:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:50

Type Values Removed Values Added
References () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-348-02 - Patch, Vendor Advisory () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-348-02 - Patch, Vendor Advisory

Information

Published : 2022-01-28 20:15

Updated : 2024-11-21 05:50


NVD link : CVE-2021-22821

Mitre link : CVE-2021-22821

CVE.ORG link : CVE-2021-22821


JSON object : View

Products Affected

schneider-electric

  • evlink_parking_evf2_firmware
  • evlink_city_evc1s22p4
  • evlink_city_evc1s7p4
  • evlink_city_evc1s22p4_firmware
  • evlink_parking_evw2
  • evlink_parking_evp2pe_firmware
  • evlink_parking_evp2pe
  • evlink_smart_wallbox_evb1a
  • evlink_parking_evw2_firmware
  • evlink_smart_wallbox_evb1a_firmware
  • evlink_city_evc1s7p4_firmware
  • evlink_parking_evf2
CWE
CWE-918

Server-Side Request Forgery (SSRF)