PT-2023-1357 · Schneider Electric · Somachine Hvac+1

Published

2023-01-10

·

Updated

2023-02-07

·

CVE-2022-2988

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions SoMachine HVAC versions prior to V2.1.0 EcoStruxure Machine Expert – HVAC versions prior to V1.4.0
Description The issue is related to a lack of protection for service data, which could allow a remote attacker to disclose protected information by sending specific messages to the server through the database server's TCP port. It is also described as an out-of-bounds write vulnerability that could cause sensitive information leakage when accessing a malicious web page from the commissioning software.
Recommendations For SoMachine HVAC versions prior to V2.1.0, update to version V2.1.0 or later to resolve the issue. For EcoStruxure Machine Expert – HVAC versions prior to V1.4.0, update to version V1.4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the commissioning software to minimize the risk of exploitation.

Fix

Memory Corruption

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2023-00686
CVE-2022-2988

Affected Products

Ecostruxure Machine Expert – Hvac
Somachine Hvac