CVE-2022-43377: High severity schneider electric netbotz 355 firmware vulnerability
Published Apr 18, 2023
·Updated
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause account takeover when a brute force attack is performed on the account.
Affected Products: NetBotz 4 - 355/450/455/550/570 (V4.7.0
and prior)
Affected Software
10 affected components
Schneider-electric Netbotz 355 Firmware>=4.0.0<=4.7.0
Schneider-electric Netbotz 355
Schneider-electric Netbotz 450 Firmware>=4.0.0<=4.7.0
Schneider-electric Netbotz 450
Schneider-electric Netbotz 455 Firmware>=4.0.0<=4.7.0
Schneider-electric Netbotz 455
Schneider-electric Netbotz 550 Firmware>=4.0.0<=4.7.0
Schneider-electric Netbotz 550
Schneider-electric Netbotz 570 Firmware>=4.0.0<=4.7.0
Schneider-electric Netbotz 570
Remediation
Event History
Apr 18, 2023
CVE Published
via MITRE·07:56 PM
Data Sourced
via MITRE·07:56 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-43377.
2
What is the title of the vulnerability?
The title of the vulnerability is A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could…
3
What is the severity of CVE-2022-43377?
The severity of CVE-2022-43377 is high with a CVSS score of 7.5.
4
Which products are affected by CVE-2022-43377?
The affected products are NetBotz 4 - 355/450/455/550/570 (V4.7.0 and prior).
5
How can CVE-2022-43377 be exploited?
CVE-2022-43377 can be exploited through a brute force attack on the account, causing account takeover.