CVE-2022-22807 Details
Description
A CWE-1021 Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause unintended modifications of the product settings or user accounts when deceiving the user to use the web interface rendered within iframes. Affected Product: EcoStruxure EV Charging Expert (formerly known as EVlink Load Management System): (HMIBSCEA53D1EDB, HMIBSCEA53D1EDS, HMIBSCEA53D1EDM, HMIBSCEA53D1EDL, HMIBSCEA53D1ESS, HMIBSCEA53D1ESM, HMIBSCEA53D1EML) (All Versions prior to SP8 (Version 01) V4.0.0.13)
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-02 | CVE | Vendor Advisory |
| https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-02 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1021 | Improper Restriction of Rendered UI Layers or Frames | [email protected] |
| CWE-1021 | Improper Restriction of Rendered UI Layers or Frames | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| schneider-electric hmibscea53d1edb firmware | < 4.0.0.13 |
CPE
Remediation
| |
| schneider-electric hmibscea53d1edb | All versions |
CPE
Remediation
| |
| schneider-electric hmibscea53d1eds firmware | < 4.0.0.13 |
CPE
Remediation
| |
| schneider-electric hmibscea53d1eds | All versions |
CPE
Remediation
| |
| schneider-electric hmibscea53d1edm firmware | < 4.0.0.13 |
CPE
Remediation
| |
| schneider-electric hmibscea53d1edm | All versions |
CPE
Remediation
| |
| schneider-electric hmibscea53d1edl firmware | < 4.0.0.13 |
CPE
Remediation
| |
| schneider-electric hmibscea53d1edl | All versions |
CPE
Remediation
| |
| schneider-electric hmibscea53d1ess firmware | < 4.0.0.13 |
CPE
Remediation
| |
| schneider-electric hmibscea53d1ess | All versions |
CPE
Remediation
| |
| schneider-electric hmibscea53d1esm firmware | < 4.0.0.13 |
CPE
Remediation
| |
| schneider-electric hmibscea53d1esm | All versions |
CPE
Remediation
| |
| schneider-electric hmibscea53d1eml firmware | < 4.0.0.13 |
CPE
Remediation
| |
| schneider-electric hmibscea53d1eml | All versions |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 22, 2023 | Modified Analysis | [email protected] |
| Jan 17, 2023 | CVE Modified | [email protected] |
| Sep 10, 2022 | Modified Analysis | [email protected] |
| May 18, 2022 | CVE Modified | [email protected] |
| Feb 16, 2022 | Initial Analysis | [email protected] |