ZDI-CAN-22161: ZDI-24-192: Schneider Electric EcoStruxure IT Gateway Hard-Coded Credentials Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Schneider Electric EcoStruxure IT Gateway. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-0865.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22161?
ZDI-CAN-22161 is a high severity vulnerability that allows local attackers to escalate privileges in Schneider Electric EcoStruxure IT Gateway.
How do I fix ZDI-CAN-22161?
To fix ZDI-CAN-22161, ensure that your installation of Schneider Electric EcoStruxure IT Gateway is updated to the latest security patches provided by the vendor.
What versions of Schneider Electric EcoStruxure IT Gateway are affected by ZDI-CAN-22161?
ZDI-CAN-22161 affects all installations of Schneider Electric EcoStruxure IT Gateway that have not been patched against this vulnerability.
Who can exploit ZDI-CAN-22161?
ZDI-CAN-22161 can be exploited by local attackers who have already gained the ability to execute low-privileged code on the affected system.
What type of attack does ZDI-CAN-22161 facilitate?
ZDI-CAN-22161 facilitates privilege escalation attacks, allowing attackers to gain elevated permissions within the affected system.