PT-2022-1851 · Schneider Electric · Easergy P5
Published
2022-01-11
·
Updated
2022-03-02
·
CVE-2022-22722
CVSS v3.1
7.5
High
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Easergy P5 versions prior to V01.401.101
Description
The issue is related to errors in managing SSH keys, which could allow an attacker to gain unauthorized access to protected information. An attacker who obtains the SSH cryptographic key for the device and gains control of the local operational network could potentially observe and manipulate traffic associated with product configuration.
Recommendations
For versions prior to V01.401.101, update to version V01.401.101 or later to resolve the issue. As a temporary workaround, consider restricting access to the SSH key management functionality to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Easergy P5