CVE-2023-5391: Critical severity schneider electric ecostruxure power monitoring expert vulnerability
Published Oct 4, 2023
·Updated
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application.
Affected Software
3 affected components
Schneider-electric Ecostruxure Power Monitoring Expert
Schneider-electric Ecostruxure Power Operation With Advanced Reports
Schneider-electric Ecostruxure Power Scada Operation With Advanced Reports
Event History
Oct 4, 2023
CVE Published
via MITRE·06:13 PM
Data Sourced
via MITRE·06:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-5391.
2
What is the severity of CVE-2023-5391?
The severity of CVE-2023-5391 is critical with a CVSS score of 9.8.
3
What is the CWE ID associated with CVE-2023-5391?
The CWE ID associated with CVE-2023-5391 is CWE-502.
4
How does this vulnerability affect Schneider-electric Ecostruxure Power Monitoring Expert?
This vulnerability affects Schneider-electric Ecostruxure Power Monitoring Expert.
5
How can an attacker exploit CVE-2023-5391?
An attacker can exploit CVE-2023-5391 by sending a specifically crafted packet to the application, allowing them to execute arbitrary code on the targeted system.