Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-34756

CVSS 8.8 · High EPSS 1.87% · P83
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-34756

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution or the crash of HTTPs stack which is used for the device Web HMI. Affected Products: Easergy P5 (V01.401.102 and prior)
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Schneider Electric Easergy P5 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Schneider Electric Easergy P5是法国施耐德电气(Schneider Electric)公司的一款适用于要求苛刻的中压应用的保护继电器。 Schneider Electric Easergy P5 V01.401.102 及之前版本存在安全漏洞,该漏洞源于不检查输入大小的缓冲区复制漏洞,攻击者利用该漏洞可以远程代码执行或用于设备 Web HMI 的 HTTPs 堆栈崩溃。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Schneider ElectricEasergy P5 Firmware ~ V01.401.102 -

II. Public POCs for CVE-2022-34756

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-34756

登录查看更多情报信息。

Same Patch Batch · Schneider Electric · 2022-07-13 · 12 CVEs total

CVE-2022-347538.8 HIGHSchneider Electric SpaceLogic C-Bus Home Controller 操作系统命令注入漏洞
CVE-2022-347597.5 HIGH多款Schneider Electric产品缓冲区错误漏洞
CVE-2022-347607.5 HIGH多款Schneider Electric产品安全漏洞
CVE-2022-347617.5 HIGH多款Schneider Electric产品代码问题漏洞
CVE-2022-347546.8 MEDIUMSchneider Electric Acti9 PowerTag Link C 安全漏洞
CVE-2022-347576.7 MEDIUMSchneider Electric Easergy P5 加密问题漏洞
CVE-2022-347625.9 MEDIUM多款Schneider Electric产品路径遍历漏洞
CVE-2022-347635.9 MEDIUM多款Schneider Electric产品数据伪造问题漏洞
CVE-2022-347645.9 MEDIUM多款Schneider Electric产品缓冲区错误漏洞
CVE-2022-347655.5 MEDIUM多款Schneider Electric产品安全漏洞
CVE-2022-347585.1 MEDIUMSchneider Electric Easergy P5 和 P3 输入验证错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2022-34756

No comments yet


Leave a comment