Citrix Data Center Expert <7.9.0: Insufficiently Protected Credentials (CWE-522)
CVE-2022-32520 Published on January 30, 2023
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. This CVE is unique from CVE-2022-32518. Affected Products: Data Center Expert (Versions prior to V7.9.0)
Vulnerability Analysis
CVE-2022-32520 is exploitable with network access, requires user interaction and a small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Products Associated with CVE-2022-32520
Want to know whenever a new CVE is published for Schneider Electric Data Center Expert? stack.watch will email you.
Affected Versions
Schneider Electric Data Center Expert:- Version All and below V7.9.0 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.