First published: Fri Nov 04 2022(Updated: )
A CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that allows adversaries with local user privileges to craft a malicious SQL query and execute as part of project migration which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider Electric EcoStruxure Operator Terminal Expert | <3.3 | |
Schneider Electric EcoStruxure Operator Terminal Expert | =3.3 | |
Schneider Electric EcoStruxure Operator Terminal Expert | =3.3-hotfix1 | |
Schneider-electric Pro-face Blue | <3.3 | |
Schneider-electric Pro-face Blue | =3.3 | |
Schneider-electric Pro-face Blue | =3.3-hotfix1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41671 is a SQL Injection vulnerability in Schneider-electric Ecostruxure Operator Terminal Expert and Schneider-electric Pro-face Blue.
CVE-2022-41671 affects Schneider-electric Ecostruxure Operator Terminal Expert versions up to and including 3.3.
CVE-2022-41671 affects Schneider-electric Pro-face Blue versions up to and including 3.3.
CVE-2022-41671 has a severity rating of 7.8 (high).
To fix CVE-2022-41671, it is recommended to apply the latest security patch or update provided by Schneider Electric.