Vulnerability Description
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote domains to access the resources (data) supplied by the server when an attacker sends a fetch request from third-party site or malicious site. Affected Products: EcoStruxure Power Commission (Versions prior to V2.22)
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Ecostruxure Power Commission | < 2.22 |
Related Weaknesses (CWE)
References
- https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+NoPatchVendor Advisory
- https://download.schneider-electric.com/files?p_enDocType=Security+and+Safety+NoPatchVendor Advisory
FAQ
What is CVE-2022-22732?
CVE-2022-22732 is a vulnerability with a CVSS score of 3.9 (LOW). A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause all remote domains to access the resources (data) supplied by the server when an attacker sends a fetch request fr...
How severe is CVE-2022-22732?
CVE-2022-22732 has been rated LOW with a CVSS base score of 3.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-22732?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Ecostruxure Power Commission.