CVE-2023-27976: High severity ecostruxure control expert vulnerability
A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause remote code execution when a valid user visits a malicious link provided through the web endpoints. Affected Products: EcoStruxure Control Expert (V15.1 and above)
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-27976?
CVE-2023-27976 is a CWE-668 vulnerability that allows remote code execution when a valid user visits a malicious link through the web endpoints.
Which products are affected by CVE-2023-27976?
The affected product is EcoStruxure Control Expert (V15.1 and above) by Schneider-electric.
What is the severity of CVE-2023-27976?
CVE-2023-27976 has a severity rating of 8.8 (High).
How can I fix CVE-2023-27976?
To fix CVE-2023-27976, it is recommended to apply the necessary patches or updates provided by Schneider-electric.
Where can I find more information about CVE-2023-27976?
You can find more information about CVE-2023-27976 in the Security and Safety Notice document by Schneider-electric, available at the provided reference link.