CVE-2021-22720 is a path traversal vulnerability (CWE-22) in Schneider Electric C-Bus Toolkit versions 1.15.7 and prior, which could lead to remote code execution during project restoration. This high-severity vulnerability (CVSS 7.2) can be exploited over the network with high privileges and no user interaction, potentially resulting in complete compromise of confidentiality, integrity, and availability. While no public exploits, Metasploit modules, or KEV entries exist, and community discussion is minimal, the FAUCET Risk Score of 66/100 indicates a notable risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.15.7CPE matchmatch criteria | cpe:2.3:a:schneider-electric:c-bus_toolkit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.