Improper Certificate Validation in EcoStruxure Cybersecurity Admin Expert by Schneider Electric
CVE-2022-32748
Key Information:
- Vendor
Schneider Electric
- Vendor
- CVE Published:
- 30 January 2023
What is CVE-2022-32748?
An improper certificate validation vulnerability exists in Schneider Electric's EcoStruxure Cybersecurity Admin Expert (CAE), which can lead to incorrect data being presented to users during device configuration. Additionally, this flaw may cause sensitive credentials to leak, potentially allowing attackers to access the configuration tool and compromise additional devices within the network. This vulnerability highlights the necessity for reliable certificate verification processes to safeguard both user data and device integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
EcoStruxure™ Cybersecurity Admin Expert (CAE) All < 2.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved