CVE-2022-22813 PUBLISHED CVSS 9.800000190734863 CRITICAL

A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key and take active control of the Courier tunneling communication network, they could potentially observe and manipulate traffic associated with product configuration.

EPSS 0.41% · 61.0th percentile

Risk Scores

CVSS v3.1
9.800000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.41%
61.0th percentile

Affected Products

VendorProductVersions
schneider-electriceasergy_p444_firmware
schneider-electriceasergy_p841_firmware
schneider-electriceasergy_p542_firmware
schneider-electriceasergy_p441_firmware
schneider-electriceasergy_p443_firmware
schneider-electriceasergy_p543_firmware
schneider-electriceasergy_p341_firmware
schneider-electriceasergy_p344_firmware
schneider-electriceasergy_p342_firmware
schneider-electriceasergy_p143_firmware
schneider-electriceasergy_p442_firmware
schneider-electriceasergy_p849_firmware
schneider-electriceasergy_p243_firmware
schneider-electriceasergy_p642_firmware
schneider-electriceasergy_p145_firmware
schneider-electriceasergy_p645_firmware
schneider-electriceasergy_p541_firmware
schneider-electriceasergy_p544_firmware
schneider-electriceasergy_p545_firmware
schneider-electriceasergy_p743_firmware

…and 14 more

Timeline

References

Open in Interactive Console →