CVE-2022-41669: High severity Schneider-electric Ecostruxure Operator Terminal Expert vulnerability
A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load a malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-41669.
What is the severity of CVE-2022-41669?
The severity of CVE-2022-41669 is high with a CVSS score of 7.8.
What is the affected software?
The affected software is Schneider-electric EcoStruxure Operator Terminal Expert v3.3 and Schneider-electric Pro-face Blue v3.3.
How can the vulnerability be exploited?
The vulnerability can be exploited by adversaries with local user privileges to load a malicious DLL which could result in execution of malicious code.
How do I fix CVE-2022-41669?
To fix CVE-2022-41669, it is recommended to apply the necessary security patches provided by Schneider-electric.