CVE-2022-0223
CVE-2022-0223
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 0.8%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
30 Jan 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow an attacker to create or overwrite critical files that are used to execute code, such as programs or libraries and cause unauthenticated code execution. Affected Products: EcoStruxure Power Commission (Versions prior to V2.22)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Affected products
Schneider Electric · EcoStruxure Power CommissionWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →