PT-2022-6396 · Schneider Electric · Ecostruxure Power Monitoring Expert

Published

2022-01-11

·

Updated

2023-01-30

·

CVE-2022-22727

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions EcoStruxure Power Monitoring Expert versions 2020 and prior
Description The issue is related to insufficient input validation, which could allow a remote attacker to view and modify equipment settings. An unauthenticated attacker may be able to impact the availability of the software or potentially affect a user's local machine by exploiting this issue, for example, through a specially crafted link.
Recommendations For versions 2020 and prior, consider restricting access to the software until a fix is available, and avoid clicking on suspicious links to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-01155
CVE-2022-22727

Affected Products

Ecostruxure Power Monitoring Expert