CVE-2023-1049: Code Injection
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-1049.
What is the severity of CVE-2023-1049?
The severity of CVE-2023-1049 is high with a CVSS score of 7.8.
Which software is affected by CVE-2023-1049?
Schneider-electric Ecostruxure Operator Terminal Expert versions up to 3.3, Schneider-electric Ecostruxure Operator Terminal Expert version 3.3, Schneider-electric Ecostruxure Operator Terminal Expert version 3.3-sp1, Schneider-electric Pro-face Blue versions up to 3.3, Schneider-electric Pro-face Blue version 3.3, and Schneider-electric Pro-face Blue version 3.3-sp1 are affected by CVE-2023-1049.
What is the CWE category of CVE-2023-1049?
CVE-2023-1049 belongs to the CWE-94 category.
How can the CVE-2023-1049 vulnerability be exploited?
The CVE-2023-1049 vulnerability can be exploited by loading a malicious project file from the local filesystem into the HMI.