First published: Tue Apr 18 2023(Updated: )
A CWE-862: Missing Authorization vulnerability exists that could allow viewing of unauthorized content, changes or deleting of content, or performing unauthorized functions when tampering the Device File Transfer settings on DCE endpoints. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Struxureware Data Center Expert | <=7.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-25552.
The severity rating of CVE-2023-25552 is high with a score of 8.1.
The CWE ID for this vulnerability is CWE-862.
The affected product is StruxureWare Data Center Expert version up to and including 7.9.2.
To fix CVE-2023-25552, it is recommended to apply the necessary security patch provided by Schneider Electric.