MEDIUM
A CWE-269: Improper Privilege Management vulnerability exists that could allow elevated functionality when guessing credentials
Published Jul 13, 2022
6.8
MEDIUMCVSS 3.1
EPSS 0.30%
Description
A CWE-269: Improper Privilege Management vulnerability exists that could allow elevated functionality when guessing credentials. Affected Products: Acti9 PowerTag Link C (A9XELC10-A) (V1.7.5 and prior), Acti9 PowerTag Link C (A9XELC10-B) (V2.12.0 and prior)
Affected products
-
Affected
- ≥ A9XELC10-A, < V1.7.5
- ≥ A9XELC10-B, < V2.12.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Schneider Electric | Acti9 PowerTag Link C | unknown | Affected
|
Configuration 1
AND
Running on/with
- n/a
Configuration 2
AND
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-193-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-193-03_Acti9_PowerTag_Link_C_Security_Notification.pdf x_refsource_MISCPatchVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-37702 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-193-03&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-193-03_Acti9_PowerTag_Link_C_Security_Notification.pdf | x_refsource_MISCPatchVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-37702 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner schneider
Published Jul 13, 2022
Updated Sep 17, 2024
Reserved Jun 28, 2022
Link CVE-2022-34754
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data