Vulnerability Details CVE-2022-24322
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause a disruption of communication between the Modicon controller and the engineering software when an attacker is able to intercept and manipulate specific Modbus response data. Affected Product: EcoStruxure Control Expert (V15.0 SP1 and prior)
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 44.7%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 4.3
Products affected by CVE-2022-24322
-
cpe:2.3:a:schneider-electric:ecostruxure_control_expert:-
-
cpe:2.3:a:schneider-electric:ecostruxure_control_expert:14.0
-
cpe:2.3:a:schneider-electric:ecostruxure_control_expert:14.1
-
cpe:2.3:a:schneider-electric:ecostruxure_control_expert:15.0