First published: Tue Apr 18 2023(Updated: )
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote code execution via the “hostname” parameter when maliciously crafted hostname syntax is entered. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Struxureware Data Center Expert | <=7.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-25550.
The severity of CVE-2023-25550 is critical.
The CWE ID of this vulnerability is CWE-94.
StruxureWare Data Center Expert (V7.9.2 and prior) is affected by CVE-2023-25550.
CVE-2023-25550 can be exploited by entering maliciously crafted hostname syntax via the "hostname" parameter to execute remote code.