PT-2022-6532 · Schneider Electric · Ecostruxure Operator Terminal Expert+1
Published
2022-10-11
·
Updated
2022-11-08
·
CVE-2022-41671
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EcoStruxure Operator Terminal Expert versions V3.3 Hotfix 1 or prior
Pro-face BLUE versions V3.3 Hotfix 1 or prior
Description
A SQL Injection vulnerability exists, allowing adversaries with local user privileges to craft a malicious SQL query and execute it as part of project migration, potentially resulting in the execution of malicious code. This issue is related to the improper neutralization of special elements used in SQL commands.
Recommendations
For EcoStruxure Operator Terminal Expert versions V3.3 Hotfix 1 or prior, consider disabling project migration functionality until a patch is available.
For Pro-face BLUE versions V3.3 Hotfix 1 or prior, restrict access to SQL query execution as a temporary workaround until a fix is provided.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ecostruxure Operator Terminal Expert
Pro-Face Blue