First published: Wed Jun 14 2023(Updated: )
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Ecostruxure Operator Terminal Expert | <3.3 | |
Schneider-electric Ecostruxure Operator Terminal Expert | =3.3 | |
Schneider-electric Ecostruxure Operator Terminal Expert | =3.3-sp1 | |
Schneider-electric Pro-face Blue | <3.3 | |
Schneider-electric Pro-face Blue | =3.3 | |
Schneider-electric Pro-face Blue | =3.3-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-1049.
The severity of CVE-2023-1049 is high with a CVSS score of 7.8.
Schneider-electric Ecostruxure Operator Terminal Expert versions up to 3.3, Schneider-electric Ecostruxure Operator Terminal Expert version 3.3, Schneider-electric Ecostruxure Operator Terminal Expert version 3.3-sp1, Schneider-electric Pro-face Blue versions up to 3.3, Schneider-electric Pro-face Blue version 3.3, and Schneider-electric Pro-face Blue version 3.3-sp1 are affected by CVE-2023-1049.
CVE-2023-1049 belongs to the CWE-94 category.
The CVE-2023-1049 vulnerability can be exploited by loading a malicious project file from the local filesystem into the HMI.