CVE-2022-22731

MEDIUM

EcoStruxure Power Commission < 2.22 - Path Traversal and Arbitrary File Write

Title source: llm
STIX 2.1

Description

A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in a function that could allow an attacker to create or overwrite critical files that are used to execute code, such as programs or libraries and cause path traversal attacks. Affected Products: EcoStruxure Power Commission (Versions prior to V2.22)

Scores

CVSS v3 6.5
EPSS 0.0056
EPSS Percentile 68.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
schneider-electric/ecostruxure_power_commission < 2.22
Published Jan 30, 2023
Tracked Since Feb 18, 2026