High severity7.9NVD Advisory· Published Jan 30, 2023· Updated Jun 17, 2026
CVE-2022-32748
CVE-2022-32748
Description
A CWE-295: Improper Certificate Validation vulnerability exists that could cause the CAE software to give wrong data to end users when using CAE to configure devices. Additionally, credentials could leak which would enable an attacker the ability to log into the configuration tool and compromise other devices in the network. Affected Products: EcoStruxure™ Cybersecurity Admin Expert (CAE) (Versions prior to 2.2)
Affected products
2- cpe:2.3:a:schneider-electric:ecostruxure_cybersecurity_admin_expert:*:*:*:*:*:*:*:*Range: <2.4
- Schneider Electric/EcoStruxure™ Cybersecurity Admin Expert (CAE)v5Range: All
Patches
Vulnerability mechanics
References
1- download.schneider-electric.com/filesnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.