PT-2022-3475 · Schneider Electric · Ecostruxure Cybersecurity Admin Expert
Published
2022-06-14
·
Updated
2023-04-03
·
CVE-2022-32748
CVSS v3.1
8.3
High
| Vector | AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EcoStruxure Cybersecurity Admin Expert (CAE) versions prior to 2.2
Description
The issue is related to improper certificate validation, which could allow a remote attacker to conduct man-in-the-middle attacks and disclose protected information. This could cause the software to provide incorrect data to end users and potentially leak credentials, enabling an attacker to log into the configuration tool and compromise other devices in the network.
Recommendations
For versions prior to 2.2, update to version 2.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the configuration tool to minimize the risk of exploitation. Additionally, ensure that all devices in the network are configured to use secure communication protocols to prevent eavesdropping and tampering.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ecostruxure Cybersecurity Admin Expert