A CWE-1021 Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause unintended modifications of the product settings or user accounts when deceiving the user to use the web interface rendered within iframes. Affected Product: EcoStruxure EV Charging Expert (formerly known as EVlink Load Management System): (HMIBSCEA53D1EDB, HMIBSCEA53D1EDS, HMIBSCEA53D1EDM, HMIBSCEA53D1EDL, HMIBSCEA53D1ESS, HMIBSCEA53D1ESM, HMIBSCEA53D1EML) (All Versions prior to SP8 (Version 01) V4.0.0.13)
Project Subscriptions
| Vendors | Products |
|---|---|
|
Schneider-electric
Subscribe
|
Hmibscea53d1edb
Subscribe
Hmibscea53d1edb Firmware
Subscribe
Hmibscea53d1edl
Subscribe
Hmibscea53d1edl Firmware
Subscribe
Hmibscea53d1edm
Subscribe
Hmibscea53d1edm Firmware
Subscribe
Hmibscea53d1eds
Subscribe
Hmibscea53d1eds Firmware
Subscribe
Hmibscea53d1eml
Subscribe
Hmibscea53d1eml Firmware
Subscribe
Hmibscea53d1esm
Subscribe
Hmibscea53d1esm Firmware
Subscribe
Hmibscea53d1ess
Subscribe
Hmibscea53d1ess Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-27950 | A CWE-1021 Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause unintended modifications of the product settings or user accounts when deceiving the user to use the web interface rendered within iframes. Affected Product: EcoStruxure EV Charging Expert (formerly known as EVlink Load Management System): (HMIBSCEA53D1EDB, HMIBSCEA53D1EDS, HMIBSCEA53D1EDM, HMIBSCEA53D1EDL, HMIBSCEA53D1ESS, HMIBSCEA53D1ESM, HMIBSCEA53D1EML) (All Versions prior to SP8 (Version 01) V4.0.0.13) |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: schneider
Published:
Updated: 2024-08-03T03:21:49.162Z
Reserved: 2022-01-07T00:00:00.000Z
Link: CVE-2022-22807
No data.
Status : Modified
Published: 2022-02-09T23:15:19.197
Modified: 2024-11-21T06:47:29.110
Link: CVE-2022-22807
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD