CVE-2022-22731: Path Traversal
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in a function that could allow an attacker to create or overwrite critical files that are used to execute code, such as programs or libraries and cause path traversal attacks. Affected Products: EcoStruxure Power Commission (Versions prior to V2.22)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22731?
The severity of CVE-2022-22731 is rated as critical with a CVSS score of 9.8.
How does CVE-2022-22731 impact Schneider-electric Ecostruxure Power Commission?
CVE-2022-22731 impacts Schneider-electric Ecostruxure Power Commission version up to 2.22, allowing path traversal attacks.
What is the CWE associated with CVE-2022-22731?
CVE-2022-22731 is associated with CWE-22: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal).
How can I mitigate the CVE-2022-22731 vulnerability?
To mitigate CVE-2022-22731, ensure to apply the necessary security patches provided by Schneider-electric.