PT-2019-5949 · Schneider Electric · Schneider Electric Software Update (Sesu) Sut Service
Published
2019-08-13
·
Updated
2022-04-20
·
CVE-2019-6834
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Schneider Electric Software Update (SESU) SUT Service component versions V2.1.1 through V2.3.0
Description
A Deserialization of Untrusted Data issue exists, which could allow an attacker to execute arbitrary code on the targeted system with SYSTEM privileges when a malicious user is authenticated. This could be exploited by placing a malicious user to be authenticated, allowing the attacker to execute arbitrary code.
Recommendations
For versions V2.1.1 through V2.3.0, update to a version outside of this range to mitigate the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Schneider Electric Software Update (Sesu) Sut Service