Lucene search

K
cveSchneiderCVE-2022-24311
HistoryFeb 09, 2022 - 11:15 p.m.

CVE-2022-24311

2022-02-0923:15:19
CWE-22
schneider
web.nvd.nist.gov
69
cve-2022-24311
cwe-22
improper limitation
pathname
restricted directory
scada
data server
remote code execution

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.018

Percentile

88.6%

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by inserting at beginning of file or create a new file in the context of the Data Server potentially leading to remote code execution when an attacker sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)

Affected configurations

Nvd
Node
schneider-electricinteractive_graphical_scada_system_data_serverRange15.0.0.22020
VendorProductVersionCPE
schneider-electricinteractive_graphical_scada_system_data_server*cpe:2.3:a:schneider-electric:interactive_graphical_scada_system_data_server:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)"
      }
    ]
  }
]

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.6

Confidence

High

EPSS

0.018

Percentile

88.6%

Related for CVE-2022-24311