Improper Condition Check in EcoStruxure Control Expert and Modicon Products
CVE-2022-45788
7.5HIGH
Key Information:
- Vendor
Schneider Electric
- Status
- Vendor
- CVE Published:
- 30 January 2023
What is CVE-2022-45788?
A vulnerability exists within Schneider Electric's EcoStruxure Control Expert and various Modicon products due to improper checks for unusual or exceptional conditions. When a malicious project file is loaded onto the controller, it can lead to extensive security risks, including arbitrary code execution, potential denial of service, and a compromise of confidentiality and integrity. The scope of this vulnerability spans multiple versions of several products, indicating a widespread potential impact across Schneider Electric's portfolio.
Affected Version(s)
EcoStruxure Control Expert All Versions
EcoStruxure Process Expert All Versions
Legacy Modicon Quantum (140CPU65*) and Premium CPUs (TSXP57*) All Versions