CWE-20: Improper Input Validation in EcoStruxure Power Monitoring Expert (Versions 2020 and prior)

CWE-20: Improper Input Validation in EcoStruxure Power Monitoring Expert (Versions 2020 and prior)

CVE-2022-22727 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A CWE-20: Improper Input Validation vulnerability exists that could allow an unauthenticated attacker to view data, change settings, impact availability of the software, or potentially impact a user�s local machine when the user clicks a specially crafted link. Affected Product: EcoStruxure Power Monitoring Expert (Versions 2020 and prior)

Learn more about our User Device Pen Test.