Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-41668


A CWE-704: Incorrect Project Conversion vulnerability exists that allows adversaries with local user privileges to load a project file from an adversary-controlled network share which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).


Published

2022-11-04T12:15:20.540

Last Modified

2024-11-21T07:23:36.310

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.0 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-704

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application schneider-electric ecostruxure_operator_terminal_expert < 3.3 Yes
Application schneider-electric ecostruxure_operator_terminal_expert 3.3 Yes
Application schneider-electric ecostruxure_operator_terminal_expert 3.3 Yes
Application schneider-electric pro-face_blue < 3.3 Yes
Application schneider-electric pro-face_blue 3.3 Yes
Application schneider-electric pro-face_blue 3.3 Yes

References