Resource Exposure Vulnerability in EcoStruxure Power Commission by Schneider Electric
CVE-2022-22732
3.9LOW
Key Information:
- Vendor
- Schneider Electric
- Vendor
- CVE Published:
- 30 January 2023
Summary
A resource exposure vulnerability exists in EcoStruxure Power Commission that can allow remote domains to access resources on the server. This occurs when an attacker sends a fetch request from a malicious third-party site, allowing unauthorized access to sensitive data. It is essential for users of affected versions to upgrade to V2.22 or later to mitigate the risk associated with this vulnerability.
Affected Version(s)
EcoStruxure Power Commission All
References
CVSS V3.1
Score:
3.9
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved