PT-2023-3273 · Schneider Electric · Struxureware Data Center Expert

Published

2023-02-14

·

Updated

2023-04-27

·

CVE-2023-25549

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions StruxureWare Data Center Expert versions prior to 7.9.2
Description A code injection issue exists, allowing for remote code execution when using a parameter of the DCE network settings endpoint. This could enable a remote attacker to execute arbitrary code.
Recommendations For versions prior to 7.9.2, update to a version newer than 7.9.2 to resolve the issue. As a temporary workaround, consider restricting access to the DCE network settings endpoint to minimize the risk of exploitation. Avoid using the vulnerable parameter in the affected endpoint until the issue is resolved.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2023-03396
CVE-2023-25549

Affected Products

Struxureware Data Center Expert