First published: Fri Nov 04 2022(Updated: )
A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load a malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric EcoStruxure Operator Terminal Expert | <3.3 | |
Schneider Electric EcoStruxure Operator Terminal Expert | =3.3 | |
Schneider Electric EcoStruxure Operator Terminal Expert | =3.3-hotfix1 | |
Pro-face Blue | <3.3 | |
Pro-face Blue | =3.3 | |
Pro-face Blue | =3.3-hotfix1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-41669.
The severity of CVE-2022-41669 is high with a CVSS score of 7.8.
The affected software is Schneider-electric EcoStruxure Operator Terminal Expert v3.3 and Schneider-electric Pro-face Blue v3.3.
The vulnerability can be exploited by adversaries with local user privileges to load a malicious DLL which could result in execution of malicious code.
To fix CVE-2022-41669, it is recommended to apply the necessary security patches provided by Schneider-electric.