CVE-2022-41670: Path Traversal
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-41670?
CVE-2022-41670 is a vulnerability that allows adversaries with local user privileges to load malicious DLL and execute malicious code.
What is the severity of CVE-2022-41670?
CVE-2022-41670 has a severity score of 7.8 (high).
Which products are affected by CVE-2022-41670?
EcoStruxure Operator Terminal Expert versions up to 3.3, EcoStruxure Operator Terminal Expert version 3.3, EcoStruxure Operator Terminal Expert version 3.3-hotfix1, Pro-face Blue versions up to 3.3, Pro-face Blue version 3.3, and Pro-face Blue version 3.3-hotfix1 are affected by CVE-2022-41670.
How can an adversary exploit CVE-2022-41670?
An adversary with local user privileges can exploit CVE-2022-41670 by loading a malicious DLL to trigger a path traversal vulnerability and execute malicious code.
Is there a fix for CVE-2022-41670?
Yes, Schneider-electric has released a security advisory with details on how to mitigate CVE-2022-41670. Please refer to the reference link for more information.