Improper Condition Check in EcoStruxure Control Expert and Modicon Products
CVE-2022-45788

7.5HIGH

Summary

A vulnerability exists within Schneider Electric's EcoStruxure Control Expert and various Modicon products due to improper checks for unusual or exceptional conditions. When a malicious project file is loaded onto the controller, it can lead to extensive security risks, including arbitrary code execution, potential denial of service, and a compromise of confidentiality and integrity. The scope of this vulnerability spans multiple versions of several products, indicating a widespread potential impact across Schneider Electric's portfolio.

Affected Version(s)

EcoStruxure Control Expert All Versions

EcoStruxure Process Expert All Versions

Legacy Modicon Quantum (140CPU65*) and Premium CPUs (TSXP57*) All Versions

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.