Aller au contenu

Fiche vulnérabilité

CVE-2023-37197 : faille élevée schneider-electric struxureware data… (CVSS 8.8)

Description

A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the mass configuration settings of endpoints on DCE.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
12 juil. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • schneider-electric struxureware data center expert

Références

Rechercher une autre vulnérabilité dans la base CVE