PT-2022-6501 · Schneider Electric · Ecostruxure Operator Terminal Expert+1

Published

2022-10-11

·

Updated

2022-11-05

·

CVE-2022-41667

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EcoStruxure Operator Terminal Expert versions V3.3 Hotfix 1 or prior Pro-face BLUE versions V3.3 Hotfix 1 or prior
Description The issue is related to an improper limitation of a pathname to a restricted directory, also known as a path traversal vulnerability. This allows adversaries with local user privileges to load a malicious DLL, potentially leading to the execution of malicious code.
Recommendations For EcoStruxure Operator Terminal Expert versions V3.3 Hotfix 1 or prior, update to a version later than V3.3 Hotfix 1 to resolve the issue. For Pro-face BLUE versions V3.3 Hotfix 1 or prior, update to a version later than V3.3 Hotfix 1 to resolve the issue. As a temporary workaround, consider restricting access to the affected software to minimize the risk of exploitation.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2023-01786
CVE-2022-41667

Affected Products

Ecostruxure Operator Terminal Expert
Pro-Face Blue