First published: Wed Feb 14 2024(Updated: )
CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with the memory of the engineering workstation.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
EcoStruxure Control Expert | <16.0 | |
Schneider Electric EcoStruxure Process Expert | <2023 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27975 has been assigned a severity rating that indicates a significant risk of unauthorized access to project files.
To mitigate CVE-2023-27975, you should apply the latest updates to EcoStruxure Control Expert and EcoStruxure Process Expert provided by Schneider Electric.
CVE-2023-27975 affects users of EcoStruxure Control Expert versions prior to 16.0 and EcoStruxure Process Expert versions prior to 2023.
CVE-2023-27975 is classified as an Insufficiently Protected Credentials vulnerability, which can lead to unauthorized access.
Yes, local users can exploit CVE-2023-27975 by tampering with the memory of the engineering workstation.