CVE Vulnerabilities

CVE-2021-22799

Insufficient Entropy

Published: Jan 28, 2022 | Modified: Feb 03, 2022
CVSS 3.x
3.8
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

A CWE-331: Insufficient Entropy vulnerability exists that could cause unintended connection from an internal network to an external network when an attacker manages to decrypt the SESU proxy password from the registry. Affected Product: Schneider Electric Software Update, V2.3.0 through V2.5.1

Weakness

The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.

Affected Software

Name Vendor Start Version End Version
Software_update Schneider-electric 2.3.0 (including) 2.5.2 (excluding)

Potential Mitigations

References