Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-34755


A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially crafted file on the target machine, which may give the attacker the ability to execute arbitrary code during the installation process initiated by a valid user. Affected Products: Easergy Builder Installer (1.7.23 and prior)


Published

2023-04-18T20:15:10.217

Last Modified

2024-11-21T07:10:07.400

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-427

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application schneider-electric easergy_builder_installer ≤ 1.7.23 Yes

References