Improper Input Validation in EcoStruxure Power Monitoring Expert by Schneider Electric
CVE-2022-22727

8.8HIGH

Key Information:

Summary

An improper input validation vulnerability exists in EcoStruxure Power Monitoring Expert that enables unauthenticated attackers to view sensitive data, modify system settings, or disrupt service availability. This issue arises when users interact with specially crafted links, which may also compromise a user's local machine. The vulnerability primarily affects version 2020 and earlier of the product, highlighting the importance of prompt security measures to safeguard against potential exploitation.

Affected Version(s)

EcoStruxure Power Monitoring Expert ( 2020 and prior) EcoStruxure Power Monitoring Expert (Versions 2020 and prior)

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.