VYPR

Power Monitoring Expert

by EcoStruxure

CVEs (3)

  • CVE-2022-22727HigFeb 4, 2022
    risk 0.57cvss 8.8epss 0.01

    A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, change settings, impact availability of the software, or potentially impact a user�s local machine when the user clicks a specially crafted link. Affected…

  • CVE-2022-22726MedFeb 4, 2022
    risk 0.42cvss 6.5epss 0.01

    A CWE-20: Improper Input Validation vulnerability exists that could allow arbitrary files on the server to be read by authenticated users through a limited operating system service account. Affected Product: EcoStruxure Power Monitoring Expert (Versions 2020 and prior)

  • CVE-2022-22804MedFeb 4, 2022
    risk 0.35cvss 5.4epss 0.00

    A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could allow an authenticated attacker to view data, change settings, or impact availability of the software when the user visits a page containing the…