PT-2022-1752 · Schneider Electric · Easergy P3
Published
2022-01-11
·
Updated
2022-03-02
·
CVE-2022-22725
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Easergy P3 versions prior to V30.205
Description
A buffer copy without checking the size of input vulnerability exists, potentially leading to a buffer overflow, causing program crashes and arbitrary code execution when specially crafted packets are sent to the device over the network. Protection functions and tripping functions via GOOSE can be impacted.
Recommendations
For versions prior to V30.205, update to version V30.205 or later to resolve the issue. As a temporary workaround, consider restricting access to the device over the network to minimize the risk of exploitation. Avoid using the GOOSE protocol until the issue is resolved.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easergy P3