CVE-2022-22732: High severity schneider electric ecostruxure power commission vulnerability
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote domains to access the resources (data) supplied by the server when an attacker sends a fetch request from third-party site or malicious site. Affected Products: EcoStruxure Power Commission (Versions prior to V2.22)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22732?
CVE-2022-22732 has been assigned a medium severity level due to its potential to expose sensitive resources.
How do I fix CVE-2022-22732?
To fix CVE-2022-22732, update your EcoStruxure Power Commission software to the latest version available prior to 2.22.
What systems are affected by CVE-2022-22732?
CVE-2022-22732 affects all versions of EcoStruxure Power Commission up to but not including version 2.22.
What type of vulnerability is CVE-2022-22732?
CVE-2022-22732 is categorized as a CWE-668 vulnerability, indicating an exposure of resources to the wrong sphere.
Can exploitation of CVE-2022-22732 lead to data breaches?
Yes, exploitation of CVE-2022-22732 can potentially allow unauthorized remote domains to access sensitive data on the server.