PT-2019-5949 · Schneider Electric · Schneider Electric Software Update (Sesu) Sut Service

Published

2019-08-13

·

Updated

2022-04-20

·

CVE-2019-6834

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Schneider Electric Software Update (SESU) SUT Service component versions V2.1.1 through V2.3.0
Description A Deserialization of Untrusted Data issue exists, which could allow an attacker to execute arbitrary code on the targeted system with SYSTEM privileges when a malicious user is authenticated. This could be exploited by placing a malicious user to be authenticated, allowing the attacker to execute arbitrary code.
Recommendations For versions V2.1.1 through V2.3.0, update to a version outside of this range to mitigate the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03841
CVE-2019-6834

Affected Products

Schneider Electric Software Update (Sesu) Sut Service