Vulnerabilities > CVE-2022-22725 - Unspecified vulnerability in Schneider-Electric Easergy P3 Firmware

047910
CVSS 8.8 - HIGH
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
low complexity
schneider-electric

Summary

A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could lead to a buffer overflow causing program crashes and arbitrary code execution when specially crafted packets are sent to the device over the network. Protection functions and tripping function via GOOSE can be impacted. Affected Product: Easergy P3 (All versions prior to V30.205)

Vulnerable Configurations

Part Description Count
OS
Schneider-Electric
1
Hardware
Schneider-Electric
1