A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow an attacker to create or overwrite critical files that are used to execute code, such as programs or libraries and cause unauthenticated code execution. Affected Products: EcoStruxure Power Commission (Versions prior to V2.22)
References
Configurations
History
21 Nov 2024, 06:38
Type | Values Removed | Values Added |
---|---|---|
References | () https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-165-05_EcoStruxure_Power_Commission_Security_Notification.pdf - Patch, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
Summary |
|
Information
Published : 2023-01-30 23:15
Updated : 2024-11-21 06:38
NVD link : CVE-2022-0223
Mitre link : CVE-2022-0223
CVE.ORG link : CVE-2022-0223
JSON object : View
Products Affected
schneider-electric
- ecostruxure_power_commission
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')