CVE-2023-37199: Code Injection
Published Jul 12, 2023
·Updated
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored.
Affected Software
1 affected component
Schneider-electric Struxureware Data Center Expert<=7.9.3
Event History
Jul 12, 2023
CVE Published
via MITRE·07:04 AM
Data Sourced
via MITRE·07:04 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this code injection vulnerability?
The vulnerability ID for this code injection vulnerability is CVE-2023-37199.
2
What is the severity level of CVE-2023-37199?
The severity level of CVE-2023-37199 is high.
3
How does the code injection vulnerability in Schneider-electric Struxureware Data Center Expert (version 7.9.3) occur?
The code injection vulnerability occurs when an admin user on DCE tampers with backups and then manually restores them.
4
What is the potential impact of this code injection vulnerability?
The code injection vulnerability could result in remote code execution.
5
How can I mitigate the code injection vulnerability in Schneider-electric Struxureware Data Center Expert (version 7.9.3)?
To mitigate the code injection vulnerability, apply the necessary security patch provided by Schneider-electric.