A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution or the crash of HTTPs stack which is used for the device Web HMI. Affected Products: Easergy P5 (V01.401.102 and prior)
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 07:10
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
References | () https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-193-04&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2022-193-04_Easergy_P5_Security_Notification.pdf - Patch, Vendor Advisory |
Information
Published : 2022-07-13 21:15
Updated : 2024-11-21 07:10
NVD link : CVE-2022-34756
Mitre link : CVE-2022-34756
CVE.ORG link : CVE-2022-34756
JSON object : View
Products Affected
schneider-electric
- easergy_p5
- easergy_p5_firmware
CWE
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')