CVE-2022-4062: High severity schneider electric ecostruxure power commission vulnerability
A CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to certain software functions when an attacker gets access to localhost interface of the EcoStruxure Power Commission application. Affected Products: EcoStruxure Power Commission (Versions prior to V2.25)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-4062?
CVE-2022-4062 is classified as a CWE-285: Improper Authorization vulnerability, which can lead to unauthorized access.
How do I fix CVE-2022-4062?
To mitigate CVE-2022-4062, upgrade the EcoStruxure Power Commission application to version 2.26 or later.
What are the potential impacts of CVE-2022-4062?
CVE-2022-4062 could allow attackers to gain unauthorized access to specific software functions if they exploit access to the localhost interface.
Which versions of EcoStruxure Power Commission are affected by CVE-2022-4062?
CVE-2022-4062 affects EcoStruxure Power Commission versions prior to 2.25.
Is there a workaround for CVE-2022-4062 until I can upgrade?
Currently, there are no documented workarounds for CVE-2022-4062; upgrading to a patched version is recommended for mitigation.