CVE-2023-37199
6.8MEDIUMA CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually
Veröffentlicht: 7/12/2023Aktualisiert: 11/21/2024
Beschreibung
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored.
KI-AnalyseKI-gestützt
Betroffene Produkte
schneider-electricstruxureware_data_center_expert
Referenzen
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-192-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-192-01.pdfVendor Advisory
- https://download.schneider-electric.com/files?p_Doc_Ref=SEVD-2023-192-01&p_enDocType=Security+and+Safety+Notice&p_File_Name=SEVD-2023-192-01.pdfVendor Advisory