IM
IronMonkey Threat Research

CVE-2022-22808 HIGH

Published: 2022-02-09 | Last Modified: 2024-11-21 | Status: Modified

Description

A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to the product when conducting cross-domain attacks based on same-origin policy or cross-site request forgery protections bypass. Affected Product: EcoStruxure EV Charging Expert (formerly known as EVlink Load Management System): (HMIBSCEA53D1EDB, HMIBSCEA53D1EDS, HMIBSCEA53D1EDM, HMIBSCEA53D1EDL, HMIBSCEA53D1ESS, HMIBSCEA53D1ESM, HMIBSCEA53D1EML) (All Versions prior to SP8 (Version 01) V4.0.0.13)

Additional Descriptions (1)

Una CWE-352: Existe una falsificación de petición en sitios cruzados (CSRF) que podría hacer que un atacante remoto obtuviera acceso no autorizado al producto al realizar ataques entre dominios basados en la política del mismo origen o en la omisión de las protecciones de falsificación de petición en sitios cruzados. Producto afectado: EcoStruxure EV Charging Expert (antes conocido como EVlink Load Management System): (HMIBSCEA53D1EDB, HMIBSCEA53D1EDS, HMIBSCEA53D1EDM, HMIBSCEA53D1EDL, HMIBSCEA53D1ESS, HMIBSCEA53D1ESM, HMIBSCEA53D1EML) (Todas las versiones anteriores a SP8 (Versión 01) V4.0.0.13)

CVSS Metrics

Base Score: 8.8 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 2.8

Impact Score: 5.9

Base Score: 6.8 (MEDIUM)

AV:N/AC:M/Au:N/C:P/I:P/A:P

Access VectorNETWORK
Access ComplexityMEDIUM
AuthenticationNONE
Confidentiality ImpactPARTIAL
Integrity ImpactPARTIAL
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 8.6

Impact Score: 6.4

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-352
[email protected] Secondary
en CWE-352

Affected Products

Vendor Product Version Update Type
schneider-electric hmibscea53d1edb_firmware * <built-in method update of dict object at 0x7e60bb885680> Operating System
schneider-electric hmibscea53d1eds_firmware * <built-in method update of dict object at 0x7e60e846e900> Operating System
schneider-electric hmibscea53d1edm_firmware * <built-in method update of dict object at 0x7e6110a553c0> Operating System
schneider-electric hmibscea53d1edl_firmware * <built-in method update of dict object at 0x7e60bb884d00> Operating System
schneider-electric hmibscea53d1ess_firmware * <built-in method update of dict object at 0x7e60bb885480> Operating System
schneider-electric hmibscea53d1esm_firmware * <built-in method update of dict object at 0x7e60bb887bc0> Operating System
schneider-electric hmibscea53d1eml_firmware * <built-in method update of dict object at 0x7e60e846ee00> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:hmibscea53d1edb_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:hmibscea53d1edb:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:hmibscea53d1eds_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:hmibscea53d1eds:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:hmibscea53d1edm_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:hmibscea53d1edm:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:hmibscea53d1edl_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:hmibscea53d1edl:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:hmibscea53d1ess_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:hmibscea53d1ess:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:hmibscea53d1esm_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:hmibscea53d1esm:-:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:hmibscea53d1eml_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:hmibscea53d1eml:-:*:*:*:*:*:*:*
Notification
Message here