ZDI-CAN-17204: ZDI-23-1113: Schneider Electric EcoStruxure Operator Terminal Expert VXDZ File Parsing Code Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStruxure Operator Terminal Expert. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-17204?
ZDI-CAN-17204 is classified as a high severity vulnerability due to the potential for arbitrary code execution by remote attackers.
How do I fix ZDI-CAN-17204?
To mitigate ZDI-CAN-17204, ensure you apply the latest patches provided by Schneider Electric for EcoStruxure Operator Terminal Expert.
Who can be attacked by ZDI-CAN-17204?
ZDI-CAN-17204 affects users of Schneider Electric EcoStruxure Operator Terminal Expert who may unknowingly visit malicious pages or open malicious files.
What are the attack vectors for ZDI-CAN-17204?
The primary attack vector for ZDI-CAN-17204 involves user interaction, requiring users to visit compromised websites or execute malicious files.
Is user interaction necessary to exploit ZDI-CAN-17204?
Yes, user interaction is crucial for exploiting ZDI-CAN-17204 as the target must perform actions that allow the attack to succeed.