Improper Verification of Cryptographic Signature in EcoStruxure and Pro-face BLUE
CVE-2022-41669
7HIGH
What is CVE-2022-41669?
A vulnerability exists in the SGIUtility component found in EcoStruxure Operator Terminal Expert and Pro-face BLUE. This vulnerability enables attackers with local user privileges to potentially load a malicious Dynamic Link Library (DLL). The exploitation of this flaw could allow adversaries to execute arbitrary code, leading to system compromise and unauthorized actions. Users of affected versions must apply updates to mitigate the risk associated with this security issue.
Affected Version(s)
EcoStruxure Operator Terminal Expert V3.3
Pro-face BLUE V3.3