Resource Exposure Vulnerability in EcoStruxure Power Commission by Schneider Electric
CVE-2022-22732

3.9LOW

Key Information:

Vendor
CVE Published:
30 January 2023

Summary

A resource exposure vulnerability exists in EcoStruxure Power Commission that can allow remote domains to access resources on the server. This occurs when an attacker sends a fetch request from a malicious third-party site, allowing unauthorized access to sensitive data. It is essential for users of affected versions to upgrade to V2.22 or later to mitigate the risk associated with this vulnerability.

Affected Version(s)

EcoStruxure Power Commission All

References

CVSS V3.1

Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.