ZDI-24-1416: Schneider Electric EcoStruxure Data Center Expert Missing Authentication Information Disclosure Vulnerability
The vulnerability allows remote attackers to disclose sensitive information on affected installations of Schneider Electric EcoStruxure Data Center Expert. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.9. The following CVEs are assigned: CVE-2024-8530.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1416?
ZDI-24-1416 has been assigned a CVSS rating of 5.9, indicating a medium severity level.
What type of vulnerability is ZDI-24-1416?
ZDI-24-1416 is a vulnerability that allows remote attackers to disclose sensitive information.
Do attackers need authentication to exploit ZDI-24-1416?
No, authentication is not required to exploit the ZDI-24-1416 vulnerability.
What software is affected by ZDI-24-1416?
ZDI-24-1416 affects Schneider Electric EcoStruxure Data Center Expert.
How can organizations protect against ZDI-24-1416?
Organizations should apply security patches provided by Schneider Electric to mitigate the risk associated with ZDI-24-1416.