ZDI-CAN-23489: ZDI-24-1416: Schneider Electric EcoStruxure Data Center Expert Missing Authentication Information Disclosure Vulnerability
Published Oct 17, 2024
·Updated
The vulnerability allows remote attackers to disclose sensitive information on affected installations of Schneider Electric EcoStruxure Data Center Expert. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.9. The following CVEs are assigned: CVE-2024-8530.
Affected Software
1 affected component
Schneider Electric EcoStruxure Data Center Expert
Event History
Oct 17, 2024
Advisory Published
via ZDI·05:00 AM
Data Sourced
via ZDI·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-23489?
The severity of ZDI-CAN-23489 is rated as 5.9 on the CVSS scale.
2
How can I fix ZDI-CAN-23489?
To fix ZDI-CAN-23489, apply the latest security patches provided by Schneider Electric for EcoStruxure Data Center Expert.
3
What information can be disclosed due to ZDI-CAN-23489?
ZDI-CAN-23489 allows remote attackers to disclose sensitive information from affected installations.
4
Is authentication required to exploit ZDI-CAN-23489?
No, authentication is not required to exploit ZDI-CAN-23489.
5
Which software is affected by ZDI-CAN-23489?
ZDI-CAN-23489 affects the Schneider Electric EcoStruxure Data Center Expert software.