PT-2022-6694 · Schneider Electric · Ecostruxure Ev Charging Expert
Eternalsakura13
+2
·
Published
2022-02-08
·
Updated
2023-02-22
·
CVE-2022-22807
CVSS v2.0
8.5
High
| Vector | AV:N/AC:L/Au:N/C:C/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
EcoStruxure EV Charging Expert versions prior to V4.0.0.13
Description
A vulnerability exists that could cause unintended modifications of the product settings or user accounts when deceiving the user to use the web interface rendered within iframes. This issue is related to improper restriction of rendered UI layers or frames.
Recommendations
For versions prior to V4.0.0.13, update to a version that includes the fix, specifically SP8 (Version 01) V4.0.0.13 or later, to resolve the issue. As a temporary workaround, consider restricting access to the web interface rendered within iframes to minimize the risk of exploitation.
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ecostruxure Ev Charging Expert