First published: Tue Apr 18 2023(Updated: )
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow a user that knows the credentials to execute unprivileged shell commands on the appliance over SSH. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Struxureware Data Center Expert | <=7.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-25555.
The severity of CVE-2023-25555 is high with a CVSS score of 8.1.
CVE-2023-25555 is a CWE-78: Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability that allows an attacker to execute unprivileged shell commands on the affected appliance over SSH.
The affected product is Schneider-electric Struxureware Data Center Expert with a version up to and including 7.9.2.
To fix CVE-2023-25555, it is recommended to update to a version of Schneider-electric Struxureware Data Center Expert that is higher than 7.9.2.