8.3
CVE-2022-32748
- EPSS 0.07%
- Veröffentlicht 30.01.2023 23:15:11
- Zuletzt bearbeitet 21.11.2024 07:06:53
- Quelle cybersecurity@se.com
- Teams Watchlist Login
- Unerledigt Login
A CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to end users when using CAE to configure devices. Additionally, credentials could leak which would enable an attacker the ability to log into the configuration tool and compromise other devices in the network. Affected Products: EcoStruxure™ Cybersecurity Admin Expert (CAE) (Versions prior to 2.2)
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Schneider-electric ≫ Ecostruxure Cybersecurity Admin Expert Version < 2.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.07% | 0.172 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.3 | 1.6 | 6 |
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
|
cybersecurity@se.com | 7.9 | 1.2 | 6 |
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
|
CWE-295 Improper Certificate Validation
The product does not validate, or incorrectly validates, a certificate.