First published: Fri Nov 04 2022(Updated: )
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric EcoStruxure Operator Terminal Expert | <3.3 | |
Schneider Electric EcoStruxure Operator Terminal Expert | =3.3 | |
Schneider Electric EcoStruxure Operator Terminal Expert | =3.3-hotfix1 | |
Schneider-electric Pro-face Blue | <3.3 | |
Schneider-electric Pro-face Blue | =3.3 | |
Schneider-electric Pro-face Blue | =3.3-hotfix1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41670 is a vulnerability that allows adversaries with local user privileges to load malicious DLL and execute malicious code.
CVE-2022-41670 has a severity score of 7.8 (high).
EcoStruxure Operator Terminal Expert versions up to 3.3, EcoStruxure Operator Terminal Expert version 3.3, EcoStruxure Operator Terminal Expert version 3.3-hotfix1, Pro-face Blue versions up to 3.3, Pro-face Blue version 3.3, and Pro-face Blue version 3.3-hotfix1 are affected by CVE-2022-41670.
An adversary with local user privileges can exploit CVE-2022-41670 by loading a malicious DLL to trigger a path traversal vulnerability and execute malicious code.
Yes, Schneider-electric has released a security advisory with details on how to mitigate CVE-2022-41670. Please refer to the reference link for more information.