The vendor explicitly identifies these products as affected by this CVE.
- Schneider Electric Easergy P5 < 01.401.101
- Summary
- A CWE-798: Use of Hard-coded Credentials vulnerability exists that could result in information disclosure. If an attacker were to obtain the SSH cryptographic key for the device and take active control of the local operational network connected to the product they could potentially observe and manipulate traffic associated with product configuration.
- Remediation
- For CVE-2022-22723 only, if customers choose not to apply the remediation provided above, they should immediately apply the following mitigation to reduce the risk of exploit: Disable the GOOSE service of the product to reduce the risk of exposure. If GOOSE is needed for the application use it only in a secure local area network. Customers should use appropriate patching methodologies when applying these patches to their systems. We strongly recommend the use of back-ups and evaluating the impact of these patches in a Test and Development environment or on an offline infrastructure. Contact Schneider Electric’s Customer Care Center if you need assistance removing a patch.
