First published: Fri Nov 04 2022(Updated: )
A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that allows adversaries with local user privileges to load a malicious DLL which could lead to execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Ecostruxure Operator Terminal Expert | <3.3 | |
Schneider-electric Ecostruxure Operator Terminal Expert | =3.3 | |
Schneider-electric Pro-face Blue | <3.3 | |
Schneider-electric Pro-face Blue | =3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41666 refers to a vulnerability that allows adversaries with local user privileges to load a malicious DLL and execute malicious code on affected products.
CVE-2022-41666 affects Schneider-electric EcoStruxure Operator Terminal Expert (v3.3 Hotfix 1 or prior) and Schneider-electric Pro-face Blue (v3.3 Hotfix 1 or prior).
CVE-2022-41666 has a severity rating of 7.8 (high).
Adversaries with local user privileges can exploit CVE-2022-41666 by loading a malicious DLL and executing malicious code on the affected systems.
To mitigate CVE-2022-41666, it is recommended to apply the necessary patches or updates provided by Schneider Electric. Additionally, users should follow best practices for system security, such as restricting user privileges and avoiding the execution of untrusted files.