IM
IronMonkey Threat Research

CVE-2022-34757 MEDIUM

Published: 2022-07-13 | Last Modified: 2024-11-21 | Status: Modified

Description

A CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists where weak cipher suites can be used for the SSH connection between Easergy Pro software and the device, which may allow an attacker to observe protected communication details. Affected Products: Easergy P5 (V01.401.102 and prior)

Additional Descriptions (1)

Una CWE-327: Se presenta una vulnerabilidad de Uso de un Algoritmo Criptográfico Roto o Arriesgado en la que pueden usarse suites de cifrado débiles para la conexión SSH entre el software Easergy Pro y el dispositivo, lo que puede permitir a un atacante observar los detalles de la comunicación protegida. Productos afectados: Easergy P5 (versiones V01.401.102 y anteriores)

CVSS Metrics

Base Score: 5.3 (MEDIUM)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactLOW
Integrity ImpactNONE
Availability ImpactNONE

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 1.4

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-327

Affected Products

Vendor Product Version Update Type
schneider-electric easergy_p5_firmware * <built-in method update of dict object at 0x7e60bb371680> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:schneider-electric:easergy_p5_firmware:*:*:*:*:*:*:*:*

Operator: OR

Vulnerable CPE
No cpe:2.3:h:schneider-electric:easergy_p5:-:*:*:*:*:*:*:*
Notification
Message here