Lucene search

K
nvd[email protected]NVD:CVE-2022-41667
HistoryNov 04, 2022 - 12:15 p.m.

CVE-2022-41667

2022-11-0412:15:19
CWE-22
web.nvd.nist.gov
cwe-22
path traversal
dll
malicious code
ecostruxure
pro-face blue

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0005 Low

EPSS

Percentile

16.5%

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that allows adversaries with local user privileges to load a malicious DLL which could lead to execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).

Affected configurations

NVD
Node
schneider-electricecostruxure_operator_terminal_expertRange<3.3
OR
schneider-electricecostruxure_operator_terminal_expertMatch3.3
OR
schneider-electricecostruxure_operator_terminal_expertMatch3.3hf1
OR
schneider-electricpro-face_blueRange<3.3
OR
schneider-electricpro-face_blueMatch3.3
OR
schneider-electricpro-face_blueMatch3.3hf1

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0005 Low

EPSS

Percentile

16.5%

Related for NVD:CVE-2022-41667