Buffer Overflow Vulnerability in EcoStruxure Control Expert by Schneider Electric
CVE-2022-37302

5.5MEDIUM

Key Information:

Vendor
CVE Published:
13 September 2022

Summary

A buffer overflow vulnerability exists in EcoStruxure Control Expert that can be triggered by opening an incorrect project file. This flaw may lead to a crash of the software, impacting functionality and user operations. It is critical for users of EcoStruxure Control Expert versions V15.1 HF001 and earlier to apply necessary precautions when handling project files to avoid potential disruptions.

Affected Version(s)

EcoStruxure Control Expert HF001 <= 15.1

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.