PT-2024-15033 · Unknown · Powersystem Center

Kelly Stich

·

Published

2024-01-08

·

Updated

2024-01-11

·

CVE-2023-6631

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PowerSYSTEM Center versions 2020 Update 16 and prior
Description The issue allows an authorized local user to insert arbitrary code into the unquoted service path, potentially leading to privilege escalation.
Recommendations For PowerSYSTEM Center versions 2020 Update 16 and prior, update to a version later than 2020 Update 16 to resolve the issue. At the moment, there is no information about additional mitigation measures.

Fix

Weakness Enumeration

Related Identifiers

CVE-2023-6631

Affected Products

Powersystem Center