CVE-2023-25554: OS Command Injection
Published Apr 18, 2023
·Updated
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that allows a local privilege escalation on the appliance when a maliciously crafted Operating System command is entered on the device.
Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
Affected Software
1 affected component
Schneider-electric Struxureware Data Center Expert<=7.9.2
Event History
Apr 18, 2023
CVE Published
via MITRE·08:34 PM
Data Sourced
via MITRE·08:34 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-25554.
2
What is the severity of CVE-2023-25554?
The severity of CVE-2023-25554 is high with a severity value of 7.8.
3
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-78.
4
Which products are affected by CVE-2023-25554?
The affected product is Schneider-electric Struxureware Data Center Expert version 7.9.2.
5
How can I fix CVE-2023-25554?
To fix CVE-2023-25554, it is recommended to update to a patched version provided by Schneider-electric.