PT-2024-2809 · Schneider Electric · Ecostruxure Control Expert+1

Published

2024-02-13

·

Updated

2024-12-11

·

CVE-2023-27975

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions EcoStruxure Control Expert (affected versions not specified) EcoStruxure Process Expert (affected versions not specified)
Description A vulnerability exists that could cause unauthorized access to the project file when a local user tampers with the memory of the engineering workstation. This issue is related to insufficiently protected credentials.
Recommendations For EcoStruxure Control Expert, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For EcoStruxure Process Expert, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

BDU:2024-02950
CVE-2023-27975

Affected Products

Ecostruxure Control Expert
Ecostruxure Process Expert