Rewterz Threat Alert – Snake Keylogger’s Malware – Active IOCs
April 4, 2022Rewterz Threat Alert – HawkEye Infostealer – Active IOCs
April 4, 2022Rewterz Threat Alert – Snake Keylogger’s Malware – Active IOCs
April 4, 2022Rewterz Threat Alert – HawkEye Infostealer – Active IOCs
April 4, 2022Severity
High
Analysis Summary
CVE-2022-0221
Schneider Electric SCADAPack Workbench could allow a remote attacker to obtain sensitive information, caused by an XML external entity (XXE) error when processing XML data by various functions. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to obtain sensitive information.
Impact
- Information Disclosure
Indicator Of Compromise
CVE
- CVE-2022-0221
Affected Vendors
- Schneider Electric
Affected Products
- Schneider Electric SCADAPack Workbench 6.6.8a
Remediation
Refer to CISA-CERT Advisory for the patch, upgrade, or suggested workaround information.