ZDI-24-1420: Schneider Electric EcoStruxure Data Center Expert XML External Entity Processing Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Schneider Electric EcoStruxure Data Center Expert. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.5. The following CVEs are assigned: CVE-2015-0250.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1420?
The severity of ZDI-24-1420 is rated as 6.5 on the CVSS scale.
What does ZDI-24-1420 affect?
ZDI-24-1420 affects installations of Schneider Electric EcoStruxure Data Center Expert.
Is authentication required to exploit ZDI-24-1420?
Yes, authentication is required to exploit the vulnerability ZDI-24-1420.
What kind of attack is associated with ZDI-24-1420?
ZDI-24-1420 allows remote attackers to disclose sensitive information.
How can I mitigate the effects of ZDI-24-1420?
Mitigation steps for ZDI-24-1420 should include updating to the latest version of Schneider Electric EcoStruxure Data Center Expert and reviewing user access controls.