Vulnerability Description
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in a function that could allow an attacker to create or overwrite critical files that are used to execute code, such as programs or libraries and cause path traversal attacks. Affected Products: EcoStruxure Power Commission (Versions prior to V2.22)
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Ecostruxure Power Commission | < 2.22 |
Related Weaknesses (CWE)
References
- https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+NoPatchVendor Advisory
- https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+NoPatchVendor Advisory
FAQ
What is CVE-2022-22731?
CVE-2022-22731 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in a function that could allow an attacker to create or overwrite critical files that are ...
How severe is CVE-2022-22731?
CVE-2022-22731 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-22731?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Ecostruxure Power Commission.