Improper Condition Check in EcoStruxure Control Expert and Modicon Products
CVE-2022-45788
7.5HIGH
Key Information:
- Vendor
- Schneider Electric
- Status
- Vendor
- CVE Published:
- 30 January 2023
Summary
A vulnerability exists within Schneider Electric's EcoStruxure Control Expert and various Modicon products due to improper checks for unusual or exceptional conditions. When a malicious project file is loaded onto the controller, it can lead to extensive security risks, including arbitrary code execution, potential denial of service, and a compromise of confidentiality and integrity. The scope of this vulnerability spans multiple versions of several products, indicating a widespread potential impact across Schneider Electric's portfolio.
Affected Version(s)
EcoStruxure Control Expert All Versions
EcoStruxure Process Expert All Versions
Legacy Modicon Quantum (140CPU65*) and Premium CPUs (TSXP57*) All Versions
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved