CVE-2023-25550: Code Injection
Published Apr 18, 2023
·Updated
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote code execution via the “hostname” parameter when maliciously crafted hostname syntax is entered.
Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
Affected Software
1 affected component
Schneider-electric Struxureware Data Center Expert<=7.9.2
Event History
Apr 18, 2023
CVE Published
via MITRE·08:36 PM
Data Sourced
via MITRE·08:36 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-25550.
2
What is the severity of CVE-2023-25550?
The severity of CVE-2023-25550 is critical.
3
What is the CWE ID of this vulnerability?
The CWE ID of this vulnerability is CWE-94.
4
Which product is affected by CVE-2023-25550?
StruxureWare Data Center Expert (V7.9.2 and prior) is affected by CVE-2023-25550.
5
How can CVE-2023-25550 be exploited?
CVE-2023-25550 can be exploited by entering maliciously crafted hostname syntax via the "hostname" parameter to execute remote code.