CVE-2022-2988

Severity CVSS v4.0:
Pending analysis
Type:
CWE-787 Out-of-bounds Write
Publication date:
30/01/2023
Last modified:
07/02/2023

Description

A CWE-787: Out-of-bounds Write vulnerability exists that could cause sensitive information leakage when accessing a malicious web page from the commissioning software. Affected Products: SoMachine HVAC (Versions prior to V2.1.0), EcoStruxure Machine Expert – HVAC (Versions prior to V1.4.0)

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:schneider-electric:ecostruxure_machine_expert_-_hvac:*:*:*:*:*:*:*:* 1.4.0 (excluding)
cpe:2.3:a:schneider-electric:somachine_hvac:*:*:*:*:*:*:*:* 2.1.0 (excluding)