PT-2023-3273 · Schneider Electric · Struxureware Data Center Expert
Published
2023-02-14
·
Updated
2023-04-27
·
CVE-2023-25549
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
StruxureWare Data Center Expert versions prior to 7.9.2
Description
A code injection issue exists, allowing for remote code execution when using a parameter of the DCE network settings endpoint. This could enable a remote attacker to execute arbitrary code.
Recommendations
For versions prior to 7.9.2, update to a version newer than 7.9.2 to resolve the issue. As a temporary workaround, consider restricting access to the DCE network settings endpoint to minimize the risk of exploitation. Avoid using the vulnerable parameter in the affected endpoint until the issue is resolved.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Struxureware Data Center Expert