CVE-2023-25552: High severity schneider electric ecostruxure data center expert vulnerability
Published Apr 18, 2023
·Updated
A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or deleting of content, or performing unauthorized functions when tampering the Device File Transfer settings on DCE endpoints.
Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
Affected Software
1 affected component
Schneider-electric Struxureware Data Center Expert<=7.9.2
Event History
Apr 18, 2023
CVE Published
via MITRE·08:33 PM
Data Sourced
via MITRE·08:33 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-25552.
2
What is the severity rating of CVE-2023-25552?
The severity rating of CVE-2023-25552 is high with a score of 8.1.
3
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-862.
4
Which products are affected by CVE-2023-25552?
The affected product is StruxureWare Data Center Expert version up to and including 7.9.2.
5
How can I fix CVE-2023-25552?
To fix CVE-2023-25552, it is recommended to apply the necessary security patch provided by Schneider Electric.