Vulnerabilities > CVE-2022-2988 - Out-of-bounds Write vulnerability in Schneider-Electric Ecostruxure Machine Expert - Hvac and Somachine Hvac

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
schneider-electric
CWE-787

Summary

A CWE-787: Out-of-bounds Write vulnerability exists that could cause sensitive information leakage when accessing a malicious web page from the commissioning software. Affected Products: SoMachine HVAC (Versions prior to V2.1.0), EcoStruxure Machine Expert – HVAC (Versions prior to V1.4.0)

Vulnerable Configurations

Part Description Count
Application
Schneider-Electric
2

Common Weakness Enumeration (CWE)