Vulnerability Description
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Schneider-Electric | Ecostruxure Operator Terminal Expert | < 3.3 |
| Schneider-Electric | Pro-Face Blue | < 3.3 |
Related Weaknesses (CWE)
References
- https://www.se.com/ww/en/download/document/SEVD-2022-284-01/PatchVendor Advisory
- https://www.se.com/ww/en/download/document/SEVD-2022-284-01/PatchVendor Advisory
FAQ
What is CVE-2022-41670?
CVE-2022-41670 is a vulnerability with a CVSS score of 7.0 (HIGH). A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load mal...
How severe is CVE-2022-41670?
CVE-2022-41670 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-41670?
Check the references section above for vendor advisories and patch information. Affected products include: Schneider-Electric Ecostruxure Operator Terminal Expert, Schneider-Electric Pro-Face Blue.