CVE-2022-22727: Input Validation
A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, change settings, impact availability of the software, or potentially impact a user?s local machine when the user clicks a specially crafted link. Affected Product: EcoStruxure Power Monitoring Expert (Versions 2020 and prior)
Other sources
A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, change settings, impact availability of the software, or potentially impact a user�s local machine when the user clicks a specially crafted link. Affected Product: EcoStruxure Power Monitoring Expert (Versions 2020 and prior)
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-22727.
What is the severity of CVE-2022-22727?
The severity of CVE-2022-22727 is critical with a CVSS score of 8.8.
How does CVE-2022-22727 impact the affected software?
CVE-2022-22727 can allow an unauthenticated attacker to view data, change settings, impact availability of the software, or potentially impact a user's local machine when the user clicks a specially crafted link.
What is the affected product for CVE-2022-22727?
The affected product for CVE-2022-22727 is EcoStruxure Power Monitoring Expert version up to and inclusive of 2020.
How can I fix CVE-2022-22727?
To fix CVE-2022-22727, it is recommended to apply the necessary patches or updates provided by Schneider-electric.