IM
IronMonkey Threat Research

CVE-2022-41668 HIGH

Published: 2022-11-04 | Last Modified: 2024-11-21 | Status: Modified

Description

A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load a project file from an adversary-controlled network share which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).

Additional Descriptions (1)

Existe una vulnerabilidad CWE-704: Conversión de Proyecto Incorrecta que permite a adversarios con privilegios de usuario local cargar un archivo de proyecto desde un recurso compartido de red controlado por el adversario, lo que podría resultar en la ejecución de código malicioso. Productos afectados: EcoStruxure Operator Terminal Expert (V3.3 Hotfix 1 o anterior), Pro-face BLUE (V3.3 Hotfix 1 o anterior).

CVSS Metrics

Base Score: 7.8 (HIGH)

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactHIGH
Integrity ImpactHIGH
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.8

Impact Score: 5.9

Weaknesses

Source Type Description
[email protected] Secondary
en CWE-704

Affected Products

Vendor Product Version Update Type
schneider-electric ecostruxure_operator_terminal_expert * <built-in method update of dict object at 0x7e611224c800> Application
schneider-electric ecostruxure_operator_terminal_expert 3.3 <built-in method update of dict object at 0x7e60ba2a4e40> Application
schneider-electric ecostruxure_operator_terminal_expert 3.3 <built-in method update of dict object at 0x7e60ba2a4fc0> Application
schneider-electric pro-face_blue * <built-in method update of dict object at 0x7e611224e200> Application
schneider-electric pro-face_blue 3.3 <built-in method update of dict object at 0x7e611224dc00> Application
schneider-electric pro-face_blue 3.3 <built-in method update of dict object at 0x7e611224c840> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:schneider-electric:ecostruxure_operator_terminal_expert:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:ecostruxure_operator_terminal_expert:3.3:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:ecostruxure_operator_terminal_expert:3.3:hf1:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:pro-face_blue:*:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:pro-face_blue:3.3:*:*:*:*:*:*:*
Yes cpe:2.3:a:schneider-electric:pro-face_blue:3.3:hf1:*:*:*:*:*:*

References

Notification
Message here