Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-22810


A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary script execution when a privileged account clicks on a malicious URL specifically crafted for the NMC pointing to a delete policy file. Affected Products: 1-Phase Uninterruptible Power Supply (UPS) using NMC2 including Smart-UPS, Symmetra, and Galaxy 3500 with Network Management Card 2 (NMC2): AP9630/AP9630CH/AP9630J, AP9631/AP9631CH/AP9631J, AP9635/AP9635J (NMC2 AOS V6.9.8 and earlier), 3-Phase Uninterruptible Power Supply (UPS) using NMC2 including Symmetra PX 250/500 (SYPX) Network Management Card 2 (NMC2): AP9630/AP9630CH/AP9630J, AP9631/AP9631CH/AP9631J, AP9635/AP9635J (NMC2 AOS V6.9.6 and earlier), 3-Phase Uninterruptible Power Supply (UPS) using NMC2 including Symmetra PX 48/96/100/160 kW UPS (PX2), Symmetra PX 20/40 kW UPS (SY3P), Gutor (SXW, GVX), and Galaxy (GVMTS, GVMSA, GVXTS, GVXSA, G7K, GFC, G9KCHU): AP9630/AP9630CH/AP9630J, AP9631/AP9631CH/AP9631J, AP9635/AP9635CH (NMC2 AOS V6.9.6 and earlier), 1-Phase Uninterruptible Power Supply (UPS) using NMC3 including Smart-UPS, Symmetra, and Galaxy 3500 with Network Management Card 3 (NMC3): AP9640/AP9640J, AP9641/AP9641J, AP9643/AP9643J (NMC3 AOS V1.4.2.1 and earlier), APC Rack Power Distribution Units (PDU) using NMC2 2G Metered/Switched Rack PDUs with embedded NMC2: AP84XX, AP86XX, AP88XX, AP89XX (NMC2 AOS V6.9.6 and earlier), APC Rack Power Distribution Units (PDU) using NMC3 2G Metered/Switched Rack PDUs with embedded NMC3: APDU99xx (NMC3 AOS V1.4.0 and earlier), APC 3-Phase Power Distribution Products using NMC2 Galaxy RPP: GRPPIP2X84 (NMC2 AOS V6.9.6 and earlier), Network Management Card 2 (NMC2) for InfraStruxure 150 kVA PDU with 84 Poles (X84P): PDPB150G6F (NMC2 AOS V6.9.6 and earlier), Network Management Card 2 for InfraStruxure 40/60kVA PDU (XPDU) PD40G6FK1-M, PD40F6FK1-M, PD40L6FK1-M, PDRPPNX10 M,PD60G6FK1, PD60F6FK1, PD60L6FK1, PDRPPNX10, PD40E5EK20-M, PD40H5EK20-M (NMC2 AOS V6.9.6 and earlier), Network Management Card 2 for Modular 150/175kVA PDU (XRDP): PDPM150G6F, PDPM150L6F, PDPM175G6H (NMC2 AOS V6.9.6 and earlier), Network Management Card 2 for 400 and 500 kVA (PMM): PMM400-ALA, PMM400-ALAX, PMM400-CUB, PMM500-ALA, PMM500-ALAX, PMM500-CUB (NMC2 AOS V6.9.6 and earlier), Network Management Card 2 for Modular PDU (XRDP2G): PDPM72F-5U, PDPM138H-5U, PDPM144F, PDPM138H-R, PDPM277H, PDPM288G6H (NMC2 AOS V6.9.6 and earlier), Rack Automatic Transfer Switches (ATS) Embedded NMC2: Rack Automatic Transfer Switches - AP44XX (ATS4G) (NMC2 AOS V6.9.6 and earlier), Network Management Card 2 (NMC2) Cooling Products: InRow Cooling for series ACRP5xx, ACRP1xx, ACRD5xx, and ACRC5xx SKUs (ACRP2G), InRow Cooling for series ACRC10x SKUs (RC10X2G), InRow Cooling for series ACRD6xx and ACRC6xx SKUs (ACRD2G), InRow Cooling Display for series ACRD3xx (ACRC2G), InRow Cooling for series ACSC1xx SKUs (SC2G), InRow Cooling for series ACRD1xx and ACRD2xx (ACRPTK2G), Ecoflair IAEC25/50 Air Economizer Display (EB2G), Uniflair SP UCF0481I, UCF0341I (UNFLRSP), Uniflair LE DX Perimeter Cooling Display for SKUs: IDAV, IDEV, IDWV, IUAV, IUEV, IUWV, IXAV, IXEV, IXWV, LDAV, LDEV, and LDWV (LEDX2G), Refrigerant Distribution Unit: ACDA9xx (RDU) (NMC2 AOS V6.9.6 and earlier), Environmental Monitoring Unit with embedded NMC2 (NB250): NetBotz NBRK0250 (NMC2 AOS V6.9.6 and earlier), and Network Management Card 2 (NMC2): AP9922 Battery Management System (BM4) (NMC2 AOS V6.9.6 and earlier)


Published

2022-01-28T20:15:09.997

Last Modified

2024-11-21T05:50:42.890

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System schneider-electric network_management_card_2_firmware ≤ 6.9.8 Yes
Hardware schneider-electric galaxy_3500 - No
Hardware schneider-electric network_management_card_2 - No
Hardware schneider-electric single-phase_symmetra - No
Hardware schneider-electric smart-ups - No
Operating System schneider-electric network_management_card_2_firmware ≤ 6.9.6 Yes
Hardware schneider-electric ap9922_battery_management_system - No
Hardware schneider-electric apc_rack_power_distribution_units - No
Hardware schneider-electric galaxy_g7x - No
Hardware schneider-electric galaxy_g9kchu - No
Hardware schneider-electric galaxy_gcxsa - No
Hardware schneider-electric galaxy_gfc - No
Hardware schneider-electric galaxy_gvmsa - No
Hardware schneider-electric galaxy_gvmts - No
Hardware schneider-electric galaxy_gvxts - No
Hardware schneider-electric galaxy_rpp_grppip2x84 - No
Hardware schneider-electric gutor_gvx - No
Hardware schneider-electric gutor_sxw - No
Hardware schneider-electric netbotz_nbrk0250 - No
Hardware schneider-electric network_management_card_2 - No
Hardware schneider-electric pd40e5ek20-m - No
Hardware schneider-electric pd40f6fk1-m - No
Hardware schneider-electric pd40g6fk1-m - No
Hardware schneider-electric pd40h5ek20-m - No
Hardware schneider-electric pd40l6fk1-m - No
Hardware schneider-electric pd60f6fk1 - No
Hardware schneider-electric pd60g6fk1 - No
Hardware schneider-electric pd60l6fk1 - No
Hardware schneider-electric pdpb150g6f - No
Hardware schneider-electric pdpm138h-5u - No
Hardware schneider-electric pdpm138h-r - No
Hardware schneider-electric pdpm144f - No
Hardware schneider-electric pdpm150g6f - No
Hardware schneider-electric pdpm150l6f - No
Hardware schneider-electric pdpm175g6h - No
Hardware schneider-electric pdpm277h - No
Hardware schneider-electric pdpm288g6h - No
Hardware schneider-electric pdpm72f-5u - No
Hardware schneider-electric pdrppnx10 - No
Hardware schneider-electric pdrppnx10m - No
Hardware schneider-electric pmm400-ala - No
Hardware schneider-electric pmm400-alax - No
Hardware schneider-electric pmm400-cub - No
Hardware schneider-electric pmm500-ala - No
Hardware schneider-electric pmm500-alax - No
Hardware schneider-electric pmm500-cub - No
Hardware schneider-electric rack_automatic_transfer_switches - No
Hardware schneider-electric symmetra_px_100 - No
Hardware schneider-electric symmetra_px_160 - No
Hardware schneider-electric symmetra_px_20 - No
Hardware schneider-electric symmetra_px_250 - No
Hardware schneider-electric symmetra_px_40 - No
Hardware schneider-electric symmetra_px_48 - No
Hardware schneider-electric symmetra_px_500 - No
Hardware schneider-electric symmetra_px_96 - No
Operating System schneider-electric network_management_card_3_firmware ≤ 1.4.2.1 Yes
Hardware schneider-electric galaxy_3500 - No
Hardware schneider-electric network_management_card_3 - No
Hardware schneider-electric single-phase_symmetra - No
Hardware schneider-electric smart-ups - No
Operating System schneider-electric network_management_card_3_firmware ≤ 1.4.0 Yes
Hardware schneider-electric apc_rack_power_distribution_units - No
Hardware schneider-electric network_management_card_3 - No

References