A CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to end users when using CAE to configure devices. Additionally, credentials could leak which would enable an attacker the ability to log into the configuration tool and compromise other devices in the network. Affected Products: EcoStruxure™ Cybersecurity Admin Expert (CAE) (Versions prior to 2.2)
Existe una vulnerabilidad CWE-295: validación de certificado incorrecta que podría provocar que el software CAE proporcione datos incorrectos a los usuarios finales cuando utilizan CAE para configurar dispositivos. Además, las credenciales podrían filtrarse, lo que permitiría a un atacante iniciar sesión en la herramienta de configuración y comprometer otros dispositivos en la red. Productos afectados: EcoStruxure? Cybersecurity Admin Expert (CAE) (Versiones anteriores a la 2.2)
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
| Attack Vector | ADJACENT_NETWORK |
|---|---|
| Attack Complexity | HIGH |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | CHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
| Source | Type | Description |
|---|---|---|
| [email protected] | Secondary |
en
CWE-295
|
| Vendor | Product | Version | Update | Type |
|---|---|---|---|---|
| schneider-electric | ecostruxure_cybersecurity_admin_expert | * | <built-in method update of dict object at 0x7e60a8896080> | Application |
| Vulnerable | CPE |
|---|---|
| Yes | cpe:2.3:a:schneider-electric:ecostruxure_cybersecurity_admin_expert:*:*:*:*:*:*:*:* |