PT-2022-1752 · Schneider Electric · Easergy P3

Published

2022-01-11

·

Updated

2022-03-02

·

CVE-2022-22725

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Easergy P3 versions prior to V30.205
Description A buffer copy without checking the size of input vulnerability exists, potentially leading to a buffer overflow, causing program crashes and arbitrary code execution when specially crafted packets are sent to the device over the network. Protection functions and tripping functions via GOOSE can be impacted.
Recommendations For versions prior to V30.205, update to version V30.205 or later to resolve the issue. As a temporary workaround, consider restricting access to the device over the network to minimize the risk of exploitation. Avoid using the GOOSE protocol until the issue is resolved.

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01050
CVE-2022-22725

Affected Products

Easergy P3