Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-41671


A CWE-89: Improper Neutralization of Special Elements used in SQL Command (‘SQL Injection’) vulnerability exists that allows adversaries with local user privileges to craft a malicious SQL query and execute as part of project migration which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).


Published

2022-11-04T15:15:10.353

Last Modified

2024-11-21T07:23:36.693

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.0 (HIGH)

Weaknesses
  • Type: Primary
    CWE-89

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application schneider-electric ecostruxure_operator_terminal_expert < 3.3 Yes
Application schneider-electric ecostruxure_operator_terminal_expert 3.3 Yes
Application schneider-electric ecostruxure_operator_terminal_expert 3.3 Yes
Application schneider-electric pro-face_blue < 3.3 Yes
Application schneider-electric pro-face_blue 3.3 Yes
Application schneider-electric pro-face_blue 3.3 Yes

References