---
cve: "CVE-2021-22769"
severity: "MEDIUM"
cvss: 5.3
epss: "65%"
vendor: "n/a"
kev: false
exploited: false
published: "2021-06-11 16:15:10"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-15T23:42:57+02:00"
---

# CVE-2021-22769

> 5.3 MEDIUM

## Beschreibung

A CWE-552: Files or Directories Accessible to External Parties vulnerability exists in Easergy T300 with firmware V2.7.1 and older that could expose files or directory content when access from an attacker is not restricted or incorrectly restricted.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Gering | warn |
| I Integrität | Keine | good |
| A Verfügbarkeit | Keine | good |

## Schwachstellen-Klasse

- **CWE-552** — Files or Directories Accessible to External Parties
  The product makes files or directories accessible to unauthorized actors, even though they should not be.

## Angriffsmuster (CAPEC)

- [CAPEC-150 — Collect Data from Common Resource Locations](https://capec.mitre.org/data/definitions/150.html) _(Severity: Medium)_
- [CAPEC-639 — Probe System Files](https://capec.mitre.org/data/definitions/639.html) _(Severity: Medium)_

## ATT&CK-Techniken

- [T1003 — OS Credential Dumping](https://attack.mitre.org/techniques/T1003/)
- [T1119 — Automated Collection](https://attack.mitre.org/techniques/T1119/)
- [T1213 — Data from Information Repositories](https://attack.mitre.org/techniques/T1213/)
- [T1530 — Data from Cloud Storage Object](https://attack.mitre.org/techniques/T1530/)
- [T1039 — Data from Network Shared Drive](https://attack.mitre.org/techniques/T1039/)
- [T1552.001 — Unsecured Credentials: Credentials in Files](https://attack.mitre.org/techniques/T1552/001/)
- [T1552.003 — Unsecured Credentials: Bash History](https://attack.mitre.org/techniques/T1552/003/)
- [T1552.004 — Unsecured Credentials: Private Keys](https://attack.mitre.org/techniques/T1552/004/)

## Referenzen

- <http://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2021-194-02>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2021-22769) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
