First published: Mon Jan 30 2023(Updated: )
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote domains to access the resources (data) supplied by the server when an attacker sends a fetch request from third-party site or malicious site. Affected Products: EcoStruxure Power Commission (Versions prior to V2.22)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Ecostruxure Power Commission | <2.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-22732 has been assigned a medium severity level due to its potential to expose sensitive resources.
To fix CVE-2022-22732, update your EcoStruxure Power Commission software to the latest version available prior to 2.22.
CVE-2022-22732 affects all versions of EcoStruxure Power Commission up to but not including version 2.22.
CVE-2022-22732 is categorized as a CWE-668 vulnerability, indicating an exposure of resources to the wrong sphere.
Yes, exploitation of CVE-2022-22732 can potentially allow unauthorized remote domains to access sensitive data on the server.