CVE-2022-41666: High severity Schneider-electric Ecostruxure Operator Terminal Expert vulnerability
A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that allows adversaries with local user privileges to load a malicious DLL which could lead to execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
EcoStruxure Operator Terminal Expertto a version that resolves this vulnerability.Fixed in V3.3 Hotfix 1 - Upgrade
Upgrade
Pro-face BLUEto a version that resolves this vulnerability.Fixed in V3.3 Hotfix 1 - Compensating control
Mitigate the local DLL-loading risk by restricting write/execute permissions in application directories so local, non-admin users cannot place or modify DLLs used by EcoStruxure Operator Terminal Expert and Pro-face BLUE.
Event History
Frequently Asked Questions
What is CVE-2022-41666?
CVE-2022-41666 refers to a vulnerability that allows adversaries with local user privileges to load a malicious DLL and execute malicious code on affected products.
Which products are affected by CVE-2022-41666?
CVE-2022-41666 affects Schneider-electric EcoStruxure Operator Terminal Expert (v3.3 Hotfix 1 or prior) and Schneider-electric Pro-face Blue (v3.3 Hotfix 1 or prior).
What is the severity of CVE-2022-41666?
CVE-2022-41666 has a severity rating of 7.8 (high).
How can adversaries exploit CVE-2022-41666?
Adversaries with local user privileges can exploit CVE-2022-41666 by loading a malicious DLL and executing malicious code on the affected systems.
How can I mitigate CVE-2022-41666?
To mitigate CVE-2022-41666, it is recommended to apply the necessary patches or updates provided by Schneider Electric. Additionally, users should follow best practices for system security, such as restricting user privileges and avoiding the execution of untrusted files.