A CWE-123: Write-what-where Condition vulnerability exists in EcoStruxure™ Control Expert (all versions) and Unity Pro (former name of EcoStruxure™ Control Expert) (all versions), that could cause a crash of the software or unexpected code execution when opening a malicious file in EcoStruxure™ Control Expert software.
oryginał ENCVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HSchneider Electric Ecostruxure Control Expert
APPSchneider-Electricwszystkie wersjeSchneider Electric Unity Pro
APPSchneider-Electricwszystkie wersje
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCEDoS
CWE
Powiązane podatności
CVE-2022-37300CRITICAL9.8PL ✓ten sam produkt
Słaby mechanizm odzyskiwania hasła w produktach Schneider Electric — dostęp przez Modbus
CVE-2022-26507CRITICAL9.8PL ✓ten sam produkt
Heap-based buffer overflow w AT&T Xmill — możliwe zdalne wykonanie kodu
CVE-2021-22779CRITICAL9.1PL ✓ten sam produkt
Authentication Bypass w produktach Schneider Electric via Modbus Spoofing
CVE-2020-28212CRITICAL9.8PL ✓ten sam produkt
Brak limitu prób uwierzytelnienia w PLC Simulator EcoStruxure Control Expert
CVE-2020-7475CRITICAL9.8PL ✓ten sam produkt
Injection (reflective DLL) w produktach Schneider Electric — przesyłanie złośliwego kodu do sterownika