IM
IronMonkey Threat Research

CVE-2022-37302 MEDIUM

Published: 2022-09-13 | Last Modified: 2024-11-21 | Status: Modified

Description

A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a crash of the Control Expert software when an incorrect project file is opened. Affected Products: EcoStruxure Control Expert(V15.1 HF001 and prior).

Additional Descriptions (1)

Una CWE-119: Se presenta una vulnerabilidad de Restricción Inapropiada de Operaciones dentro de los Límites de un Búfer de Memoria que podría causar un bloqueo del software Control Expert cuando es abierto un archivo de proyecto incorrecto. Productos afectados: EcoStruxure Control Expert (versiones V15.1 HF001 y anteriores)

CVSS Metrics

Base Score: 5.5 (MEDIUM)

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionREQUIRED
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.8

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-119

Affected Products

Vendor Product Version Update Type
schneider-electric ecostruxure_control_expert * <built-in method update of dict object at 0x7e60bae0e1c0> Application
schneider-electric ecostruxure_control_expert 15.1 <built-in method update of dict object at 0x7e60bae0ed00> Application
schneider-electric ecostruxure_control_expert 15.1 <built-in method update of dict object at 0x7e60e86ce040> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:ecostruxure_control_expert:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:ecostruxure_control_expert:15.1:-:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:ecostruxure_control_expert:15.1:hf001:*:*:*:*:*:*

References

Notification
Message here