CVE-2023-27975: High severity ecostruxure control expert vulnerability
CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with the memory of the engineering workstation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27975?
CVE-2023-27975 has been assigned a severity rating that indicates a significant risk of unauthorized access to project files.
How do I fix CVE-2023-27975?
To mitigate CVE-2023-27975, you should apply the latest updates to EcoStruxure Control Expert and EcoStruxure Process Expert provided by Schneider Electric.
Who is affected by CVE-2023-27975?
CVE-2023-27975 affects users of EcoStruxure Control Expert versions prior to 16.0 and EcoStruxure Process Expert versions prior to 2023.
What type of vulnerability is CVE-2023-27975?
CVE-2023-27975 is classified as an Insufficiently Protected Credentials vulnerability, which can lead to unauthorized access.
Can local users exploit CVE-2023-27975?
Yes, local users can exploit CVE-2023-27975 by tampering with the memory of the engineering workstation.