CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with the memory of the engineering workstation.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NSchneider Electric Ecostruxure Control Expert
APPSchneider-Electric< 16.0Schneider Electric Ecostruxure Process Expert
APPSchneider-Electric< 2023
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2022-37300CRITICAL9.8PL ✓same product
Słaby mechanizm odzyskiwania hasła w produktach Schneider Electric — dostęp przez Modbus
CVE-2022-26507CRITICAL9.8PL ✓same product
Heap-based buffer overflow w AT&T Xmill — możliwe zdalne wykonanie kodu
CVE-2021-22779CRITICAL9.1PL ✓same product
Authentication Bypass w produktach Schneider Electric via Modbus Spoofing
CVE-2020-28212CRITICAL9.8PL ✓same product
Brak limitu prób uwierzytelnienia w PLC Simulator EcoStruxure Control Expert
CVE-2020-7475CRITICAL9.8PL ✓same product
Injection (reflective DLL) w produktach Schneider Electric — przesyłanie złośliwego kodu do sterownika