CVE-2022-41671: SQL Injection
A CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that allows adversaries with local user privileges to craft a malicious SQL query and execute as part of project migration which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-41671?
CVE-2022-41671 is a SQL Injection vulnerability in Schneider-electric Ecostruxure Operator Terminal Expert and Schneider-electric Pro-face Blue.
How does CVE-2022-41671 affect Schneider-electric Ecostruxure Operator Terminal Expert?
CVE-2022-41671 affects Schneider-electric Ecostruxure Operator Terminal Expert versions up to and including 3.3.
How does CVE-2022-41671 affect Schneider-electric Pro-face Blue?
CVE-2022-41671 affects Schneider-electric Pro-face Blue versions up to and including 3.3.
What is the severity of CVE-2022-41671?
CVE-2022-41671 has a severity rating of 7.8 (high).
How can I fix CVE-2022-41671?
To fix CVE-2022-41671, it is recommended to apply the latest security patch or update provided by Schneider Electric.