Improper Input Validation in EcoStruxure Power Monitoring Expert by Schneider Electric
CVE-2022-22727
8.8HIGH
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 4 February 2022
Summary
An improper input validation vulnerability exists in EcoStruxure Power Monitoring Expert that enables unauthenticated attackers to view sensitive data, modify system settings, or disrupt service availability. This issue arises when users interact with specially crafted links, which may also compromise a user's local machine. The vulnerability primarily affects version 2020 and earlier of the product, highlighting the importance of prompt security measures to safeguard against potential exploitation.
Affected Version(s)
EcoStruxure Power Monitoring Expert ( 2020 and prior) EcoStruxure Power Monitoring Expert (Versions 2020 and prior)
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved