First published: Mon Jan 30 2023(Updated: )
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in a function that could allow an attacker to create or overwrite critical files that are used to execute code, such as programs or libraries and cause path traversal attacks. Affected Products: EcoStruxure Power Commission (Versions prior to V2.22)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Ecostruxure Power Commission | <2.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-22731 is rated as critical with a CVSS score of 9.8.
CVE-2022-22731 impacts Schneider-electric Ecostruxure Power Commission version up to 2.22, allowing path traversal attacks.
CVE-2022-22731 is associated with CWE-22: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal).
To mitigate CVE-2022-22731, ensure to apply the necessary security patches provided by Schneider-electric.