Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-41666


A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that allows adversaries with local user privileges to load a malicious DLL which could lead to execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).


Published

2022-11-04T05:15:09.040

Last Modified

2024-11-21T07:23:36.033

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.0 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-347

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application schneider-electric ecostruxure_operator_terminal_expert < 3.3 Yes
Application schneider-electric ecostruxure_operator_terminal_expert 3.3 Yes
Application schneider-electric pro-face_blue < 3.3 Yes
Application schneider-electric pro-face_blue 3.3 Yes

References