CVE-2023-37198: Code Injection
Published Jul 12, 2023
·Updated
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE uploads or tampers with install packages.
Affected Software
1 affected component
Schneider-electric Struxureware Data Center Expert<=7.9.3
Event History
Jul 12, 2023
CVE Published
via MITRE·06:44 AM
Data Sourced
via MITRE·06:44 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-37198.
2
What is the severity level of CVE-2023-37198?
CVE-2023-37198 has a severity level of high, with a value of 7.
3
What is the CWE category of CVE-2023-37198?
CVE-2023-37198 falls under the CWE-94 category, which is an Improper Control of Generation of Code (Code Injection) vulnerability.
4
Which software versions are affected by CVE-2023-37198?
Schneider-electric Struxureware Data Center Expert versions up to and including 7.9.3 are affected by CVE-2023-37198.
5
How can the CVE-2023-37198 vulnerability be exploited?
The CVE-2023-37198 vulnerability can be exploited by an admin user on DCE who uploads or tampers with install packages, potentially leading to remote code execution.