PT-2022-6502 · Schneider Electric · Ecostruxure Operator Terminal Expert+1
CVE-2022-41668
·
Published
2022-10-11
·
Updated
2022-11-05
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
EcoStruxure Operator Terminal Expert versions prior to V3.3 Hotfix 1
Pro-face BLUE versions prior to V3.3 Hotfix 1
Description
The issue is related to incorrect project conversion, which can be exploited to execute malicious code. An adversary with local user privileges can load a project file from a controlled network share, potentially leading to the execution of arbitrary code.
Recommendations
For EcoStruxure Operator Terminal Expert versions prior to V3.3 Hotfix 1, update to a version later than V3.3 Hotfix 1.
For Pro-face BLUE versions prior to V3.3 Hotfix 1, update to a version later than V3.3 Hotfix 1.
As a temporary workaround, consider restricting access to project files from untrusted network shares to minimize the risk of exploitation.
Fix
Incorrect Type Conversion or Cast
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ecostruxure Operator Terminal Expert
Pro-Face Blue