Vulnerability Details CVE-2022-22727
A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, change settings, impact availability of the software, or potentially impact a user�s local machine when the user clicks a specially crafted link. Affected Product: EcoStruxure Power Monitoring Expert (Versions 2020 and prior)
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 73.8%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 9.3
Products affected by CVE-2022-22727
-
cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:2020
-
cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:7.0
-
cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:8.0
-
cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:8.2
-
cpe:2.3:a:schneider-electric:ecostruxure_power_monitoring_expert:9.0