CVE-2023-6409: High severity ecostruxure control expert vulnerability
Published Feb 14, 2024
·Updated
CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application password when opening the file with EcoStruxure Control Expert.
Affected Software
2 affected components
Schneider-electric Ecostruxure Control Expert<16.0
Schneider-electric Ecostruxure Process Expert<2023
Event History
Feb 14, 2024
CVE Published
via MITRE·04:47 PM
Data Sourced
via MITRE·04:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-6409?
CVE-2023-6409 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2023-6409?
To remediate CVE-2023-6409, ensure that no hard-coded credentials are used in your project files.
3
What software versions are affected by CVE-2023-6409?
CVE-2023-6409 affects EcoStruxure Control Expert versions up to 16.0 and EcoStruxure Process Expert versions up to 2023.
4
What impact does CVE-2023-6409 have on security?
CVE-2023-6409 can lead to unauthorized access to project files protected by application passwords.
5
Is there a workaround for CVE-2023-6409?
Currently, there is no official workaround for CVE-2023-6409; the best practice is to avoid using hard-coded credentials.