IM
IronMonkey Threat Research

CVE-2022-22722 HIGH

Published: 2022-02-04 | Last Modified: 2024-11-21 | Status: Modified

Description

A CWE-798: Use of Hard-coded Credentials vulnerability exists that could result in information disclosure. If an attacker were to obtain the SSH cryptographic key for the device and take active control of the local operational network connected to the product they could potentially observe and manipulate traffic associated with product configuration. Affected Product: Easergy P5 (All firmware versions prior to V01.401.101)

Additional Descriptions (1)

Una CWE-798: Se presenta un uso de credenciales embebidas que podría resultar en una divulgación de información. Si un atacante obtuviera la clave criptográfica SSH del dispositivo y tomara el control activo de la red operativa local conectada al producto, podría observar y manipular el tráfico asociado a la configuración del producto. Producto afectado: Easergy P5 (todas las versiones de firmware anteriores a V01.401.101)

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack VectorADJACENT_NETWORK
Attack ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.6

Impact Score: 5.9

Base Score: 5.4 (MEDIUM)

AV:A/AC:M/Au:N/C:P/I:P/A:P

Access VectorADJACENT_NETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 5.5

Impact Score: 6.4

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-798

Affected Products

Vendor Product Version Update Type
schneider-electric easergy_p5_firmware * <built-in method update of dict object at 0x7e60bae0c800> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:easergy_p5_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:easergy_p5:-:*:*:*:*:*:*:*
Notification
Message here