PT-2022-6502 · Schneider Electric · Ecostruxure Operator Terminal Expert+1

CVE-2022-41668

·

Published

2022-10-11

·

Updated

2022-11-05

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EcoStruxure Operator Terminal Expert versions prior to V3.3 Hotfix 1 Pro-face BLUE versions prior to V3.3 Hotfix 1
Description The issue is related to incorrect project conversion, which can be exploited to execute malicious code. An adversary with local user privileges can load a project file from a controlled network share, potentially leading to the execution of arbitrary code.
Recommendations For EcoStruxure Operator Terminal Expert versions prior to V3.3 Hotfix 1, update to a version later than V3.3 Hotfix 1. For Pro-face BLUE versions prior to V3.3 Hotfix 1, update to a version later than V3.3 Hotfix 1. As a temporary workaround, consider restricting access to project files from untrusted network shares to minimize the risk of exploitation.

Fix

Incorrect Type Conversion or Cast

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01787
CVE-2022-41668

Affected Products

Ecostruxure Operator Terminal Expert
Pro-Face Blue