PT-2019-5949 · Schneider Electric · Schneider Electric Software Update (Sesu) Sut Service
Publicado
2019-08-13
·
Atualizado
2022-04-20
·
CVE-2019-6834
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Schneider Electric Software Update (SESU) SUT Service component versions V2.1.1 through V2.3.0
Description
A Deserialization of Untrusted Data issue exists, which could allow an attacker to execute arbitrary code on the targeted system with SYSTEM privileges when a malicious user is authenticated. This could be exploited by placing a malicious user to be authenticated, allowing the attacker to execute arbitrary code.
Recommendations
For versions V2.1.1 through V2.3.0, update to a version outside of this range to mitigate the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Schneider Electric Software Update (Sesu) Sut Service