First published: Fri Feb 04 2022(Updated: )
A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, change settings, impact availability of the software, or potentially impact a user?s local machine when the user clicks a specially crafted link. Affected Product: EcoStruxure Power Monitoring Expert (Versions 2020 and prior)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric EcoStruxure Power Monitoring Expert | <=2020 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-22727.
The severity of CVE-2022-22727 is critical with a CVSS score of 8.8.
CVE-2022-22727 can allow an unauthenticated attacker to view data, change settings, impact availability of the software, or potentially impact a user's local machine when the user clicks a specially crafted link.
The affected product for CVE-2022-22727 is EcoStruxure Power Monitoring Expert version up to and inclusive of 2020.
To fix CVE-2022-22727, it is recommended to apply the necessary patches or updates provided by Schneider-electric.