CVE-2022-22723
published 2022-02-04CVE-2022-22723: A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could lead to a buffer overflow causing program crashes and arbitrary code…
PriorityP354high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
2.82%
84.9th percentile
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could lead to a buffer overflow causing program crashes and arbitrary code execution when specially crafted packets are sent to the device over the network. Protection functions and tripping function via GOOSE can be impacted. Affected Product: Easergy P5 (All firmware versions prior to V01.401.101)
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| schneider-electric | easergy_p5_firmware | < 01.401.101 | 01.401.101 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.08.3HIGHAV:A/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mm7j-7gq2-x4fr: A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could lead to a buffer overflow causing program crashes and arbitrary
ghsa_unreviewed·2022-02-11
CVE-2022-22723 [HIGH] CWE-120 GHSA-mm7j-7gq2-x4fr: A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could lead to a buffer overflow causing program crashes and arbitrary
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could lead to a buffer overflow causing program crashes and arbitrary code execution when specially crafted packets are sent to the device over the network. Protection functions and tripping function via GOOSE can be impacted. Affected Product: Easergy P5 (All firmware versions prior to V01.401.101)
CISA ICS
Schneider Electric Easergy P5 and P3 (Update A)
cisa_ics·2022-02-24·CVSS 7.5
[HIGH] Schneider Electric Easergy P5 and P3 (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Schneider Electric Easergy P5 and P3 (Update A)
Last RevisedJuly 12, 2022
Alert CodeICSA-22-055-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.8
- ATTENTION: Low attack complexity
- Vendor: Schneider Electric
- Equipment: Easergy P5 and P3
--------- Begin Update A Part 1 of 4 ---------
- Vulnerabilities: Use of Hard-Coded Credentials, Classic Buffer Overflow, and Improper Input Validation
--------- End Update A Part 1 of 4 ---------
## 2. UPDATE
This updated advisory is a follow-up to the original advisory titled ICSA-22-055-03 Schneider Electric Easergy P5 and P3 that was publi
No detection rules found.
No public exploits indexed.
2022-02-04
Published