PT-2022-6694 · Schneider Electric · Ecostruxure Ev Charging Expert

·

CVE-2022-22807

·

Published

2022-02-08

·

Updated

2023-02-22

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions EcoStruxure EV Charging Expert versions prior to V4.0.0.13
Description A vulnerability exists that could cause unintended modifications of the product settings or user accounts when deceiving the user to use the web interface rendered within iframes. This issue is related to improper restriction of rendered UI layers or frames.
Recommendations For versions prior to V4.0.0.13, update to a version that includes the fix, specifically SP8 (Version 01) V4.0.0.13 or later, to resolve the issue. As a temporary workaround, consider restricting access to the web interface rendered within iframes to minimize the risk of exploitation.

Fix

Clickjacking

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-03430
CVE-2022-22807

Affected Products

Ecostruxure Ev Charging Expert