PT-2022-1851 · Schneider Electric · Easergy P5

Published

2022-01-11

·

Updated

2022-03-02

·

CVE-2022-22722

CVSS v3.1

7.5

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Easergy P5 versions prior to V01.401.101
Description The issue is related to errors in managing SSH keys, which could allow an attacker to gain unauthorized access to protected information. An attacker who obtains the SSH cryptographic key for the device and gains control of the local operational network could potentially observe and manipulate traffic associated with product configuration.
Recommendations For versions prior to V01.401.101, update to version V01.401.101 or later to resolve the issue. As a temporary workaround, consider restricting access to the SSH key management functionality to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01320
CVE-2022-22722

Affected Products

Easergy P5