CVE-2021-22815Sensitive Information Exposure in Network Management Card 2 Firmware

Severity
5.3MEDIUMNVD
EPSS
0.3%
top 51.65%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 28
Latest updateJan 29

Description

A CWE-200: Information Exposure vulnerability exists which could cause the troubleshooting archive to be accessed. Affected Products: 1-Phase Uninterruptible Power Supply (UPS) using NMC2 including Smart-UPS, Symmetra, and Galaxy 3500 with Network Management Card 2 (NMC2): AP9630/AP9630CH/AP9630J, AP9631/AP9631CH/AP9631J, AP9635/AP9635J (NMC2 AOS V6.9.8 and earlier), 3-Phase Uninterruptible Power Supply (UPS) using NMC2 including Symmetra PX 250/500 (SYPX) Network Management Card 2 (NMC2): AP963

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

🔴Vulnerability Details

2
GHSA
GHSA-8rfr-9f7v-chvx: A CWE-200: Information Exposure vulnerability exists which could cause the troubleshooting archive to be accessed2022-01-29
CVEList
CVE-2021-22815: A CWE-200: Information Exposure vulnerability exists which could cause the troubleshooting archive to be accessed2022-01-28
CVE-2021-22815 — Sensitive Information Exposure | cvebase