VulnerabilityModified
CVE-2022-22813
A CWE-798: Use of Hard-coded Credentials vulnerability exists.
CRITICAL 9.8EPSS 1.07%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.07%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A CWE-798: Use of Hard-coded Credentials vulnerability exists. If an attacker were to obtain the TLS cryptographic key and take active control of the Courier tunneling communication network, they could potentially observe and manipulate traffic associated with product configuration.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.07% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798
- Affected
- schneider-electric/easergy p141 firmware · schneider-electric/easergy p142 firmware · schneider-electric/easergy p143 firmware · schneider-electric/easergy p145 firmware · schneider-electric/easergy p241 firmware · schneider-electric/easergy p242 firmware · schneider-electric/easergy p243 firmware · schneider-electric/easergy p342 firmware · schneider-electric/easergy p343 firmware · schneider-electric/easergy p344 firmware · schneider-electric/easergy p345 firmware · schneider-electric/easergy p441 firmware · schneider-electric/easergy p442 firmware · schneider-electric/easergy p443 firmware · schneider-electric/easergy p444 firmware · schneider-electric/easergy p445 firmware · schneider-electric/easergy p446 firmware · schneider-electric/easergy p541 firmware · schneider-electric/easergy p542 firmware · schneider-electric/easergy p543 firmware · +13 more
- Source
- cybersecurity@se.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.