PT-2023-1357 · Schneider Electric · Somachine Hvac+1
CVE-2022-2988
·
Publicado
2023-01-10
·
Atualizado
2023-02-07
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SoMachine HVAC versions prior to V2.1.0
EcoStruxure Machine Expert – HVAC versions prior to V1.4.0
Description
The issue is related to a lack of protection for service data, which could allow a remote attacker to disclose protected information by sending specific messages to the server through the database server's TCP port. It is also described as an out-of-bounds write vulnerability that could cause sensitive information leakage when accessing a malicious web page from the commissioning software.
Recommendations
For SoMachine HVAC versions prior to V2.1.0, update to version V2.1.0 or later to resolve the issue.
For EcoStruxure Machine Expert – HVAC versions prior to V1.4.0, update to version V1.4.0 or later to resolve the issue.
As a temporary workaround, consider restricting access to the commissioning software to minimize the risk of exploitation.
Correção
Memory Corruption
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Ecostruxure Machine Expert – Hvac
Somachine Hvac