CVE-2023-7032: High severity schneider electric easergy studio vulnerability
Published Jan 9, 2024
·Updated
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker logged in with a user level account to gain higher privileges by providing a harmful serialized object.
Affected Software
1 affected component
Schneider-electric Easergy Studio<=9.3.5
Event History
Jan 9, 2024
CVE Published
via MITRE·07:30 PM
Data Sourced
via MITRE·07:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-7032?
CVE-2023-7032 is classified as a critical severity vulnerability.
2
How do I fix CVE-2023-7032?
To fix CVE-2023-7032, update Schneider Electric Easergy Studio to version 9.3.6 or later.
3
Who is affected by CVE-2023-7032?
CVE-2023-7032 affects users of Schneider Electric Easergy Studio versions up to and including 9.3.5.
4
What does CVE-2023-7032 exploit?
CVE-2023-7032 exploits a deserialization of untrusted data vulnerability which could elevate user privileges.
5
Can an attacker exploit CVE-2023-7032 without a user account?
No, an attacker must be logged in with a user-level account to exploit CVE-2023-7032.