Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-2988


A CWE-787: Out-of-bounds Write vulnerability exists that could cause sensitive information leakage when accessing a malicious web page from the commissioning software. Affected Products: SoMachine HVAC (Versions prior to V2.1.0), EcoStruxure Machine Expert – HVAC (Versions prior to V1.4.0)


Published

2023-01-30T11:15:08.807

Last Modified

2024-11-21T07:02:02.433

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-787

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application schneider-electric ecostruxure_machine_expert_-_hvac < 1.4.0 Yes
Application schneider-electric somachine_hvac < 2.1.0 Yes

References