Vulnerability Description
A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to the product when conducting cross-domain attacks based on same-origin policy or cross-site request forgery protections bypass. Affected Product: EcoStruxure EV Charging Expert (formerly known as EVlink Load Management System): (HMIBSCEA53D1EDB, HMIBSCEA53D1EDS, HMIBSCEA53D1EDM, HMIBSCEA53D1EDL, HMIBSCEA53D1ESS, HMIBSCEA53D1ESM, HMIBSCEA53D1EML) (All Versions prior to SP8 (Version 01) V4.0.0.13)
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Hmibscea53D1Edb Firmware | < 4.0.0.13 |
| Schneider-Electric | Hmibscea53D1Edb | - |
| Schneider-Electric | Hmibscea53D1Eds Firmware | < 4.0.0.13 |
| Schneider-Electric | Hmibscea53D1Eds | - |
| Schneider-Electric | Hmibscea53D1Edm Firmware | < 4.0.0.13 |
| Schneider-Electric | Hmibscea53D1Edm | - |
| Schneider-Electric | Hmibscea53D1Edl Firmware | < 4.0.0.13 |
| Schneider-Electric | Hmibscea53D1Edl | - |
| Schneider-Electric | Hmibscea53D1Ess Firmware | < 4.0.0.13 |
| Schneider-Electric | Hmibscea53D1Ess | - |
| Schneider-Electric | Hmibscea53D1Esm Firmware | < 4.0.0.13 |
| Schneider-Electric | Hmibscea53D1Esm | - |
| Schneider-Electric | Hmibscea53D1Eml Firmware | < 4.0.0.13 |
| Schneider-Electric | Hmibscea53D1Eml | - |
Related Weaknesses (CWE)
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-02PatchVendor Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-02PatchVendor Advisory
FAQ
What is CVE-2022-22808?
CVE-2022-22808 is a vulnerability with a CVSS score of 8.8 (HIGH). A CWE-352: Cross-Site Request Forgery (CSRF) exists that could cause a remote attacker to gain unauthorized access to the product when conducting cross-domain attacks based on same-origin policy or cr...
How severe is CVE-2022-22808?
CVE-2022-22808 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-22808?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Hmibscea53D1Edb Firmware, Schneider-Electric Hmibscea53D1Edb, Schneider-Electric Hmibscea53D1Eds Firmware, Schneider-Electric Hmibscea53D1Eds, Schneider-Electric Hmibscea53D1Edm Firmware.