ZDI-24-354: Schneider Electric EcoStruxure Power Design - Ecodial BinSerializer Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStruxure Power Design - Ecodial. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-2229.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-354?
The severity of ZDI-24-354 is classified as high due to the potential for remote code execution.
How do I fix ZDI-24-354?
To fix ZDI-24-354, update to the latest version of Schneider Electric EcoStruxure Power Design - Ecodial as provided by the vendor.
Who is affected by ZDI-24-354?
ZDI-24-354 affects installations of Schneider Electric EcoStruxure Power Design - Ecodial.
What type of attack is ZDI-24-354 associated with?
ZDI-24-354 is associated with remote code execution attacks that require user interaction.
What should I do if I suspect exploitation of ZDI-24-354?
If you suspect exploitation of ZDI-24-354, immediately revoke access permissions, isolate affected systems, and apply the necessary patches.