Improper Verification of Cryptographic Signature in EcoStruxure and Pro-face BLUE
CVE-2022-41669
7HIGH
Summary
A vulnerability exists in the SGIUtility component found in EcoStruxure Operator Terminal Expert and Pro-face BLUE. This vulnerability enables attackers with local user privileges to potentially load a malicious Dynamic Link Library (DLL). The exploitation of this flaw could allow adversaries to execute arbitrary code, leading to system compromise and unauthorized actions. Users of affected versions must apply updates to mitigate the risk associated with this security issue.
Affected Version(s)
EcoStruxure Operator Terminal Expert V3.3
Pro-face BLUE V3.3
References
CVSS V3.1
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved