PT-2022-6694 · Schneider Electric · Ecostruxure Ev Charging Expert

Eternalsakura13

+2

·

Published

2022-02-08

·

Updated

2023-02-22

·

CVE-2022-22807

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions EcoStruxure EV Charging Expert versions prior to V4.0.0.13
Description A vulnerability exists that could cause unintended modifications of the product settings or user accounts when deceiving the user to use the web interface rendered within iframes. This issue is related to improper restriction of rendered UI layers or frames.
Recommendations For versions prior to V4.0.0.13, update to a version that includes the fix, specifically SP8 (Version 01) V4.0.0.13 or later, to resolve the issue. As a temporary workaround, consider restricting access to the web interface rendered within iframes to minimize the risk of exploitation.

Fix

Clickjacking

Weakness Enumeration

Related Identifiers

BDU:2023-03430
CVE-2022-22807

Affected Products

Ecostruxure Ev Charging Expert