First published: Wed Feb 01 2023(Updated: )
A CWE-285: Improper Authorization vulnerability exists that could cause unauthorized access to certain software functions when an attacker gets access to localhost interface of the EcoStruxure Power Commission application. Affected Products: EcoStruxure Power Commission (Versions prior to V2.25)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Ecostruxure Power Commission | <2.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-4062 is classified as a CWE-285: Improper Authorization vulnerability, which can lead to unauthorized access.
To mitigate CVE-2022-4062, upgrade the EcoStruxure Power Commission application to version 2.26 or later.
CVE-2022-4062 could allow attackers to gain unauthorized access to specific software functions if they exploit access to the localhost interface.
CVE-2022-4062 affects EcoStruxure Power Commission versions prior to 2.25.
Currently, there are no documented workarounds for CVE-2022-4062; upgrading to a patched version is recommended for mitigation.