CVE-2022-22723
Severity CVSS v4.0:
Pending analysis
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
04/02/2022
Last modified:
10/02/2022
Description
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could lead to a buffer overflow causing program crashes and arbitrary code execution when specially crafted packets are sent to the device over the network. Protection functions and tripping function via GOOSE can be impacted. Affected Product: Easergy P5 (All firmware versions prior to V01.401.101)
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
8.30
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:schneider-electric:easergy_p5_firmware:*:*:*:*:*:*:*:* | 01.401.101 (excluding) | |
| cpe:2.3:h:schneider-electric:easergy_p5:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



