Vulnerability Description
A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key and take active control of the Courier tunneling communication network, they could potentially observe and manipulate traffic associated with product configuration.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Easergy P141 Firmware | - |
| Schneider-Electric | Easergy P141 | - |
| Schneider-Electric | Easergy P142 Firmware | - |
| Schneider-Electric | Easergy P142 | - |
| Schneider-Electric | Easergy P143 Firmware | - |
| Schneider-Electric | Easergy P143 | - |
| Schneider-Electric | Easergy P145 Firmware | - |
| Schneider-Electric | Easergy P145 | - |
| Schneider-Electric | Easergy P241 Firmware | - |
| Schneider-Electric | Easergy P241 | - |
| Schneider-Electric | Easergy P242 Firmware | - |
| Schneider-Electric | Easergy P242 | - |
| Schneider-Electric | Easergy P243 Firmware | - |
| Schneider-Electric | Easergy P243 | - |
| Schneider-Electric | Easergy P342 Firmware | - |
| Schneider-Electric | Easergy P342 | - |
| Schneider-Electric | Easergy P343 Firmware | - |
| Schneider-Electric | Easergy P343 | - |
| Schneider-Electric | Easergy P344 Firmware | - |
| Schneider-Electric | Easergy P344 | - |
Related Weaknesses (CWE)
References
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-03Vendor Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2022-039-03Vendor Advisory
FAQ
What is CVE-2022-22813?
CVE-2022-22813 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key and take active control of the Courier tunneling communication network, they coul...
How severe is CVE-2022-22813?
CVE-2022-22813 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-22813?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Easergy P141 Firmware, Schneider-Electric Easergy P141, Schneider-Electric Easergy P142 Firmware, Schneider-Electric Easergy P142, Schneider-Electric Easergy P143 Firmware.