PT-2022-6395 · Schneider Electric · Ecostruxure Power Commission

Published

2022-12-13

·

Updated

2023-04-03

·

CVE-2022-4062

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EcoStruxure Power Commission versions prior to V2.25
Description A vulnerability exists that could cause unauthorized access to certain software functions when an attacker gains access to the localhost interface of the EcoStruxure Power Commission application. This issue is related to improper authorization procedures, which could allow an attacker to elevate their privileges.
Recommendations For versions prior to V2.25, update to version V2.25 or later to resolve the issue. As a temporary workaround, consider restricting access to the localhost interface of the EcoStruxure Power Commission application to minimize the risk of exploitation.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

BDU:2023-01154
CVE-2022-4062

Affected Products

Ecostruxure Power Commission