Buffer Overflow Vulnerability in EcoStruxure Control Expert by Schneider Electric
CVE-2022-37302
5.5MEDIUM
Summary
A buffer overflow vulnerability exists in EcoStruxure Control Expert that can be triggered by opening an incorrect project file. This flaw may lead to a crash of the software, impacting functionality and user operations. It is critical for users of EcoStruxure Control Expert versions V15.1 HF001 and earlier to apply necessary precautions when handling project files to avoid potential disruptions.
Affected Version(s)
EcoStruxure Control Expert HF001 <= 15.1
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved