First published: Tue Apr 18 2023(Updated: )
A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially crafted file on the target machine, which may give the attacker the ability to execute arbitrary code during the installation process initiated by a valid user. Affected Products: Easergy Builder Installer (1.7.23 and prior)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Easergy Builder | <=1.7.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-34755.
The severity of CVE-2022-34755 is medium with a severity value of 6.7.
The CWE ID for this vulnerability is CWE-427.
The affected software version of CVE-2022-34755 is Schneider-electric Easergy Builder Installer 1.7.23.
The vulnerability CVE-2022-34755 can be exploited by an attacker with a local privileged account who places a specially crafted file on the target machine, allowing them to execute arbitrary code during the installation process initiated by a valid user.