Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-34755

Опубликовано: 18 апр. 2023
Источник: nvd
CVSS3: 6.3
CVSS3: 6.7
EPSS Низкий

Описание

A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially crafted file on the target machine, which may give the attacker the ability to execute arbitrary code during the installation process initiated by a valid user. Affected Products: Easergy Builder Installer (1.7.23 and prior)

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:schneider-electric:easergy_builder_installer:*:*:*:*:*:*:*:*
Версия до 1.7.23 (включая)

EPSS

Процентиль: 22%
0.00074
Низкий

6.3 Medium

CVSS3

6.7 Medium

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 6.3
github
больше 2 лет назад

A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially crafted file on the target machine, which may give the attacker the ability to execute arbitrary code during the installation process initiated by a valid user. Affected Products: Easergy Builder Installer (1.7.23 and prior)

CVSS3: 6.3
fstec
почти 3 года назад

Уязвимость программного средства для настройки контроллеров Schneider Electric Easergy Builder, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 22%
0.00074
Низкий

6.3 Medium

CVSS3

6.7 Medium

CVSS3

Дефекты

CWE-427