High
CVE-2021-22707
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2021-22707
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prior to R8 V3.4.0.1 ) that could allow an attacker to issue unauthorized commands to the charging station web server with administrative privileges.
Add Assessment
Ratings
-
Attacker ValueHigh
-
ExploitabilityVery High
Technical Analysis
According to https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-06 this is a hardcoded password issue in EVlink City / Parking / Smart Wallbox Charging Stations that would grant attackers administrative level control over a EVlink City / Parking / Smart Wallbox Charging Stations web server. These types of devices may not be updated regularly due to the need for them to be running constantly throughout the city, so I can imagine implementing a proper patching strategy will be paramount for ensuring this patch gets applied quickly, as this type of vulnerability could either be used for something simple like just resetting the amount a user has to pay to charge their car, or for gaining further access to city infrastructure, which could be used as a precursor to more targeted attacks.
Would you also like to delete your Exploited in the Wild Report?
Delete Assessment Only Delete Assessment and Exploited in the Wild ReportCVSS V3 Severity and Metrics
General Information
Vendors
- schneider-electric
Products
- evlink city evc1s22p4 firmware,
- evlink city evc1s7p4 firmware,
- evlink parking ev.2 firmware,
- evlink parking evf2 firmware,
- evlink parking evw2 firmware,
- evlink smart wallbox evb1a firmware
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: