ZDI-CAN-23203: ZDI-24-1417: Schneider Electric EcoStruxure Data Center Expert Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability
Published Oct 17, 2024
·Updated
The vulnerability allows remote attackers to execute arbitrary code on affected installations of Schneider Electric EcoStruxure Data Center Expert. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2024-8531.
Affected Software
1 affected component
Schneider Electric EcoStruxure Data Center Expert
Event History
Oct 17, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-23203?
The severity of ZDI-CAN-23203 is rated 7.2 on the CVSS scale.
2
How do I fix ZDI-CAN-23203?
To mitigate ZDI-CAN-23203, update your installation of Schneider Electric EcoStruxure Data Center Expert to the latest available version.
3
What type of attacks are possible with ZDI-CAN-23203?
ZDI-CAN-23203 allows remote attackers to execute arbitrary code on affected installations.
4
Is authentication required to exploit ZDI-CAN-23203?
Yes, authentication is required to exploit the ZDI-CAN-23203 vulnerability.
5
Which software is affected by ZDI-CAN-23203?
ZDI-CAN-23203 affects Schneider Electric EcoStruxure Data Center Expert installations.