First published: Tue Apr 18 2023(Updated: )
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause remote code execution when a valid user visits a malicious link provided through the web endpoints. Affected Products: EcoStruxure Control Expert (V15.1 and above)
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Ecostruxure Control Expert | >=15.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27976 is a CWE-668 vulnerability that allows remote code execution when a valid user visits a malicious link through the web endpoints.
The affected product is EcoStruxure Control Expert (V15.1 and above) by Schneider-electric.
CVE-2023-27976 has a severity rating of 8.8 (High).
To fix CVE-2023-27976, it is recommended to apply the necessary patches or updates provided by Schneider-electric.
You can find more information about CVE-2023-27976 in the Security and Safety Notice document by Schneider-electric, available at the provided reference link.