QID 591044
Date Published: 2022-09-15
QID 591044: Schneider Electric EcoStruxure Cybersecurity Admin Expert Multiple Vulnerabilities (SEVD-2022-165-08)
AFFECTED PRODUCTS
EcoStruxure Cybersecurity Admin Expert (CAE) Versions 2.2 and prior
QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys
Successful exploitation of these vulnerabilities may risk man-in-the-middle and/or device spoofing attacks, which could result in the total compromise of devices configured by the CAE.
Solution
Customers are advised to refer to CERT MITIGATIONS section SEVD-2022-165-08 for affected packages and patching details.
Vendor References
- SEVD-2022-165-08 -
www.se.com/ww/en/download/document/SEVD-2022-165-08/
CVEs related to QID 591044
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SEVD-2022-165-08 |
|