ZDI-CAN-21032: ZDI-24-354: Schneider Electric EcoStruxure Power Design - Ecodial BinSerializer Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStruxure Power Design - Ecodial. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-2229.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21032?
The severity of ZDI-CAN-21032 is high due to its potential to allow remote code execution.
How do I fix ZDI-CAN-21032?
To fix ZDI-CAN-21032, update Schneider Electric EcoStruxure Power Design - Ecodial to the latest version provided by the vendor.
What software is affected by ZDI-CAN-21032?
ZDI-CAN-21032 affects Schneider Electric EcoStruxure Power Design - Ecodial.
What is the nature of the attack for ZDI-CAN-21032?
The attack for ZDI-CAN-21032 requires user interaction, such as visiting a malicious page or opening a malicious file.
Can ZDI-CAN-21032 be exploited remotely?
Yes, ZDI-CAN-21032 can be exploited by remote attackers if the user interacts with the malicious content.