VYPR

Network Management Card

by Schneider Electric

CVEs (7)

  • CVE-2021-22814MedJan 28, 2022
    risk 0.40cvss 6.1epss 0.01

    A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists which could cause arbritrary script execution when a malicious file is read and displayed. Affected Products: 1-Phase Uninterruptible Power Supply (UPS) using NMC2…

  • CVE-2021-22813MedJan 28, 2022
    risk 0.40cvss 6.1epss 0.01

    A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary script execution when a privileged account clicks on a malicious URL specifically crafted for the NMC pointing to an edit policy file.…

  • CVE-2021-22812MedJan 28, 2022
    risk 0.40cvss 6.1epss 0.01

    A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary script execution when a privileged account clicks on a malicious URL specifically crafted for the NMC. Affected Products: 1-Phase…

  • CVE-2021-22811MedJan 28, 2022
    risk 0.40cvss 6.1epss 0.01

    A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause script execution when the request of a privileged account accessing the vulnerable web page is intercepted. Affected Products: 1-Phase…

  • CVE-2021-22810MedJan 28, 2022
    risk 0.40cvss 6.1epss 0.01

    A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary script execution when a privileged account clicks on a malicious URL specifically crafted for the NMC pointing to a delete policy file.…

  • CVE-2021-22815MedJan 28, 2022
    risk 0.35cvss 5.3epss 0.01

    A CWE-200: Information Exposure vulnerability exists which could cause the troubleshooting archive to be accessed. Affected Products: 1-Phase Uninterruptible Power Supply (UPS) using NMC2 including Smart-UPS, Symmetra, and Galaxy 3500 with Network Management Card 2 (NMC2):…

  • CVE-2023-6032MedNov 15, 2023
    risk 0.34cvss 5.3epss 0.01

    A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumeration and file download when an attacker navigates to the Network Management Card via HTTPS.