{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-17T19:12:46.397","vulnerabilities":[{"cve":{"id":"CVE-2022-41669","sourceIdentifier":"cybersecurity@se.com","published":"2022-11-04T13:15:11.250","lastModified":"2024-11-21T07:23:36.437","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"A CWE-347: Improper Verification of Cryptographic Signature vulnerability exists in the SGIUtility component that allows adversaries with local user privileges to load a malicious DLL which could result in execution of malicious code. Affected Products: EcoStruxure Operator Terminal Expert(V3.3 Hotfix 1 or prior), Pro-face BLUE(V3.3 Hotfix1 or prior)."},{"lang":"es","value":"Existe una vulnerabilidad CWE-347: Verificación Inadecuada de Firma Criptográfica en el componente SGIUtility que permite a adversarios con privilegios de usuario local cargar una DLL maliciosa que podría resultar en la ejecución de código malicioso. Productos afectados: EcoStruxure Operator Terminal Expert (V3.3 Hotfix 1 o anterior), Pro-face BLUE (V3.3 Hotfix 1 o anterior)."}],"metrics":{"cvssMetricV31":[{"source":"cybersecurity@se.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.0,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.0,"impactScore":5.9},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"weaknesses":[{"source":"cybersecurity@se.com","type":"Secondary","description":[{"lang":"en","value":"CWE-347"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:schneider-electric:ecostruxure_operator_terminal_expert:*:*:*:*:*:*:*:*","versionEndExcluding":"3.3","matchCriteriaId":"5705916B-E189-4314-AD32-C8D42991DFA2"},{"vulnerable":true,"criteria":"cpe:2.3:a:schneider-electric:ecostruxure_operator_terminal_expert:3.3:-:*:*:*:*:*:*","matchCriteriaId":"A6EAEC62-F689-43A2-8EDB-68867661ED92"},{"vulnerable":true,"criteria":"cpe:2.3:a:schneider-electric:ecostruxure_operator_terminal_expert:3.3:hotfix1:*:*:*:*:*:*","matchCriteriaId":"54A2C97D-9FE0-4E01-B9BE-D5508CFEEB5A"},{"vulnerable":true,"criteria":"cpe:2.3:a:schneider-electric:pro-face_blue:*:*:*:*:*:*:*:*","versionEndExcluding":"3.3","matchCriteriaId":"297C4149-AA1F-4033-BD74-0FB908783399"},{"vulnerable":true,"criteria":"cpe:2.3:a:schneider-electric:pro-face_blue:3.3:-:*:*:*:*:*:*","matchCriteriaId":"FB229476-7E0C-46ED-817D-C9A72250CC5D"},{"vulnerable":true,"criteria":"cpe:2.3:a:schneider-electric:pro-face_blue:3.3:hotfix1:*:*:*:*:*:*","matchCriteriaId":"C893D88A-656A-4748-841C-5851D34E9C69"}]}]}],"references":[{"url":"https://www.se.com/ww/en/download/document/SEVD-2022-284-01/","source":"cybersecurity@se.com","tags":["Patch","Vendor Advisory"]},{"url":"https://www.se.com/ww/en/download/document/SEVD-2022-284-01/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"]}]}}]}